[CVE-2025-53149] Kernel Streaming WOW Thunk Service 驱动中的堆缓冲区溢出
crowdfense.com | 漏洞 | 高危 | CVE-2025-53149 | #windows-kernel | #patch-analysis | #cve-2025-53149 | #ksthunk | #heap-overflow | #driver-vulnerability | #kernel-streaming
摘要
深入分析 CVE-2025-53149:Windows Kernel Streaming WOW Thunk 服务驱动 ksthunk.sys 中的堆缓冲区溢出,缺陷位于 CKSAutomationThunk::HandleArrayProperty 函数,微软已于 2025 年 8 月补丁修复。
- CVSS
- 7.8
- 发布时间
- 收录时间
Skip to content