CVE-2025-21226
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Summary
CVE-2025-21226 is a newly disclosed vulnerability affecting Windows Digital Media. This elevation of privilege issue allows an attacker, who has already gained access to a target system, to escalate their privileges and gain administrative control. Exploitation of this vulnerability could lead to significant damage, including unauthorized access to sensitive data or the installation of malware. Microsoft has released a patch to address this issue, and it is highly recommended that all affected systems are updated as soon as possible to mitigate the risk. Organizations should also remain vigilant for any signs of unauthorized access or suspicious activity on their networks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft