Slovak cybersecurity firm ESET reports that a recently patched zero-day vulnerability in the Windows Win32 Kernel Subsystem has begun to be exploited in attacks since March 2023.
See also: Apple patches third zero-day vulnerability this year

The security flaw was fixed in Windows updates released with this month's Patch Tuesday. The flaw is now tracked as CVE-2025-24983 and was reported to Microsoft by ESET researcher Filip Jurčacko.
The zero-day vulnerability in the Windows Kernel Subsystem results from a vulnerability that could allow attackers with limited privileges to gain SYSTEM privileges without requiring user interaction. However, the company described these attacks as particularly complex, as successful exploitation requires malicious actors to create a race condition.
ESET announced on Tuesday that a zero-day exploit exploiting the CVE-2025-24983 vulnerability “first appeared” in March 2023 on systems infected with the PipeMagic.
This exploit is focused exclusively on older versions of Windows, such as Windows Server 2012 R2 and Windows 8.1, which are no longer supported by Microsoft. However, the vulnerability also affects more recent versions of Windows, including Windows Server 2016 and Windows 10, which are still supported, with Windows 10 version 1809 and earlier.
See also: Microsoft Patch Tuesday March 2025: Fixes 57 vulnerabilities

PipeMagic was discovered by Kaspersky in 2022 and can be used to collect sensitive data, provides attackers with full remote access to infected devices, and enables them to deploy additional malicious payloads to move laterally through victims' networks.
In 2023, Kaspersky saw it deployed in Nokoyawa ransomware that exploited another Windows zero-day, a privilege escalation flaw in the Common Log File System Driver tracked as CVE-2023-28252.
Yesterday, CISA added all six zero-days to the List of Known Exploitable Vulnerabilities, ordering Federal Civilian Executive Branch (FCEB) to secure their systems by April 1, as required by Binding Operational Directive (BOD) 22-01.
See also: Android Security Updates – March 2025: Fix 44 Vulnerabilities
The term zero-day refers to a security hole or vulnerability in software or a system that is unknown to its manufacturer or developer and can be exploited by a malicious user, such as in the case of the Windows Kernel Subsystem. The word “zero-day” refers to the fact that the manufacturer has not yet discovered the problem or has not released a patch or update to fix it. These vulnerabilities are particularly dangerous because attackers can exploit them before the manufacturer takes steps to fix them, so “zero-day” refers to the first moment the vulnerability is exploited.
Source: bleepingcomputer
