CVE-2025-49667 is an elevation-of-privilege vulnerability in the Windows Win32 Kernel Subsystem, specifically in the Win32K ICOMP component. The flaw is a double-free condition in kernel memory management. Available reporting indicates the issue arises from improper state tracking during destruction of interdependent graphical objects, allowing the same kernel heap allocation to be freed twice. A local authenticated attacker can trigger the vulnerable condition through crafted interaction with Win32K graphical system calls. The resulting kernel heap corruption may enable controlled reuse of freed memory and manipulation of adjacent kernel structures, creating a path to execution in kernel context and privilege escalation to SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) local privilege escalation exploit for CVE-2025-49667, a double free vulnerability in the Windows kernel component win32k.sys. The exploit is implemented in a single C++ file (exploit.cpp) and is accompanied by a detailed README.md that explains the vulnerability, affected systems, and usage instructions. The exploit targets unpatched Windows 10 systems (versions 1909 through 22H2) and does not work on Windows 11 or fully patched systems. The attack vector is strictly local: the attacker must have the ability to execute code on the target machine. The exploit works by triggering a double free in kernel memory, spraying the heap with controlled data, and overwriting a function pointer to escalate privileges. Upon successful exploitation, the code spawns a SYSTEM-level command prompt (cmd.exe), granting the attacker full control over the system. The repository is well-structured, with clear compilation and usage instructions, and is intended for educational and research purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation double-free vulnerability in the Windows Win32K driver's ICOMP component that can allow authenticated attackers to gain elevated, potentially SYSTEM-level, privileges.
A local elevation of privilege vulnerability in the Windows Win32 Kernel Subsystem (Win32K - ICOMP) caused by a double free condition, allowing an authorized attacker with low privileges to gain SYSTEM privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.