CVE-2025-50168

HIGH

Windows Win32K - ICOMP - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-50168. PoCs published by D4m0n.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-50168, leveraging DirectComposition and IoRing primitives to achieve out-of-bounds (OOB) writes. The exploit demonstrates a local privilege escalation (LPE) by manipulating kernel objects and achieving arbitrary write capabilities.

Description

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Exploits (1)

github WORKING POC 142 stars
by D4m0n · cpoc
https://github.com/D4m0n/CVE-2025-50168-pwn2own-berlin-2025

This repository contains a functional exploit for CVE-2025-50168, leveraging DirectComposition and IoRing primitives to achieve out-of-bounds (OOB) writes. The exploit demonstrates a local privilege escalation (LPE) by manipulating kernel objects and achieving arbitrary write capabilities.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Microsoft Windows (specific version not specified)
No auth needed
Prerequisites: Windows system with vulnerable DirectComposition and IoRing implementations
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0107
EPSS Percentile 78.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-843 CWE-122
Status published
Products (5)
microsoft/windows_11_22h2 < 10.0.22621.5768
microsoft/windows_11_23h2 < 10.0.22631.5768
microsoft/windows_11_24h2 < 10.0.26100.4851
microsoft/windows_server_2022_23h2 < 10.0.25398.1791
microsoft/windows_server_2025 < 10.0.26100.4851
Published Aug 12, 2025
Tracked Since Feb 18, 2026