CVE-2025-50168

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

History

19 Aug 2025, 14:20

Type Values Removed Values Added
First Time Microsoft windows 11 23h2
Microsoft windows Server 2025
Microsoft windows 11 24h2
Microsoft windows Server 2022 23h2
Microsoft
Microsoft windows 11 22h2
CPE cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50168 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50168 - Vendor Advisory

13 Aug 2025, 17:34

Type Values Removed Values Added
Summary
  • (es) Acceso a recursos mediante un tipo incompatible ('confusión de tipos') en Windows Win32K - ICOMP permite que un atacante autorizado eleve privilegios localmente.

12 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 18:15

Updated : 2025-08-19 14:20


NVD link : CVE-2025-50168

Mitre link : CVE-2025-50168

CVE.ORG link : CVE-2025-50168


JSON object : View

Products Affected

microsoft

  • windows_11_23h2
  • windows_11_22h2
  • windows_11_24h2
  • windows_server_2025
  • windows_server_2022_23h2
CWE
CWE-122

Heap-based Buffer Overflow

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')