CVE-2025-50168

Published Aug 12, 2025

Last updated 3 months ago

CVSS high 7.8
Windows Win32K
ICOMP

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-50168 is a type confusion vulnerability found in the Windows Win32K - ICOMP component. Disclosed on August 12, 2025, the vulnerability affects Windows 11 and Windows Server 2025. The vulnerability is due to the access of a resource using an incompatible type. Successful exploitation of this vulnerability allows an authorized attacker to elevate privileges locally. Microsoft has released security updates to address this vulnerability in affected versions of Windows 11 and Windows Server 2025.

Description
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.