CVE-2025-21217

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 693

Summary

CVE-2025-21217 is a newly disclosed vulnerability affecting Windows systems. This issue permits an attacker to conduct NTLM (NT LAN Manager) spoofing, which enables them to trick other computers into trusting their malicious entity as a legitimate one. By forging NTLM responses, attackers can gain unauthorized access to sensitive data or resources, potentially leading to further exploitation and compromise. Microsoft has released a security update to address this vulnerability, and it is recommended that all Windows users install the patch as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft