Get the latest tech news

Heap-based buffer overflow in Kernel Streaming


Technical deep-dive into CVE-2025-53149, a heap-based buffer overflow in the Windows Kernel Streaming WOW Thunk Service driver (ksthunk.sys).

One such case is CVE-2025-53149, a heap-based buffer overflow in the Kernel Streaming WOW Thunk Service Driver, which Microsoft patched on August 12, 2025. It provides a low-latency, high-performance architecture that allows devices and applications to efficiently process and transport large volumes of data, such as audio and video. KSThunk, short for “Kernel Streaming WOW Thunk Service,” is a specific component within the Windows operating system that plays a crucial role in maintaining backwards compatibility for multimedia applications.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of heap

heap

Photo of Kernel Streaming

Kernel Streaming

Related news:

News photo

Problems with the heap

News photo

Heap-overflowing Llama.cpp to RCE

News photo

Diablo 4 celebrates its first anniversary by giving you "a goblin's heap" of free gifts