CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,489 vulnerabilities with CWE-416
CVE-2025-54912 HIGH
Windows BitLocker - Use-After-Free
CVSS 7.8
CVE-2025-54911 HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Authenticated Use-After-Free in BitLocker
CVSS 7.3
CVE-2025-54908 HIGH
Microsoft Office PowerPoint - Use-After-Free
CVSS 7.8
CVE-2025-54906 HIGH
Microsoft 365 Apps and Office - Use-After-Free
CVSS 7.8
CVE-2025-54904 HIGH
Microsoft Excel - Use-After-Free
CVSS 7.8
CVE-2025-54903 HIGH
Microsoft Excel - Use-After-Free
CVSS 7.8
CVE-2025-54902 HIGH
Microsoft Excel - Out-of-bounds Read
CVSS 7.8
CVE-2025-54896 HIGH
Microsoft Excel - Use-After-Free
CVSS 7.8
CVE-2025-54112 HIGH
Windows 10/11, Server 2016-2019 Use-After-Free in Virtual Hard Drive
CVSS 7.0
CVE-2025-54111 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2016-2019 - Use-After-Free in XAML Phone DatePickerFlyout
CVSS 7.8
CVE-2025-54108 HIGH
Windows 11 24H2 / Server 2025 < 10.0.26100.6508 Privilege Escalation via Race Condition
CVSS 7.0
CVE-2025-54105 HIGH
Windows 11 24H2/Server 2022 23H2/2025 Privilege Escalation via Brokering File System Race Condition
CVSS 7.0
CVE-2025-54103 HIGH
Windows 10/11, Server 2022/2025 Use-After-Free in Windows Management Services
CVSS 7.4
CVE-2025-54102 HIGH
Windows 10/11, Server 2016-2022 Privilege Escalation via Connected Devices Platform UAF
CVSS 7.8
CVE-2025-54101 MEDIUM
Windows SMBv3 Client - Use-After-Free Remote Code Execution
CVSS 4.8
CVE-2025-54092 HIGH
Windows 10/11, Server 2019-2025 Hyper-V Race Condition Privilege Escalation
CVSS 7.8
CVE-2025-53807 HIGH
Microsoft Graphics Component - Privilege Escalation
CVSS 7.0
CVE-2025-53802 HIGH
Windows Bluetooth Service - Privilege Escalation
CVSS 7.0
CVE-2025-36854 HIGH
.NET 6.0 <= 6.0.36 - Use-After-Free via HTTP/3 Stream Closure
CVSS 8.1
CVE-2025-3212 MEDIUM
Arm 5th Gen GPU Architecture Kernel Driver r41p0-r49p4, r50p0-r51p0 - Use-After-Free
CVSS 5.3
CVE-2025-39721 MEDIUM
Linux Kernel 5.18-6.16.3 - Use-After-Free in QAT Driver Workqueue Handling
CVSS 5.5
CVE-2025-39717 HIGH
Linux Kernel 6.15-6.16.3 - Use-After-Free via open_tree_attr Without OPEN_TREE_CLONE
CVSS 7.8
CVE-2025-39711 HIGH
Linux Kernel 6.6-6.6.102, 6.7-6.12.43, 6.13-6.16.3 - Use-After-Free in mei_cl_set_disconnected
CVSS 7.8
CVE-2025-39698 MEDIUM
Linux Kernel - Use-After-Free in io_uring/futex
CVSS 5.5
CVE-2025-39691 HIGH
Linux Kernel 2.6.13-6.16.4 - Use-After-Free in Buffer Head Handling
CVSS 7.8
Details
Vulnerabilities 7,489
Exploit Likelihood High