CVE-2025-21229
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 125
Summary
CVE-2025-21229 is an elevation of privilege vulnerability affecting Windows Digital Media. Attackers can exploit this vulnerability to gain higher system privileges, potentially leading to the compromise of sensitive information or the installation of malware. The vulnerability is due to improper input validation in the Windows Media Player component. It is recommended that affected systems be updated with the Microsoft Security Bulletin MS22-079 to mitigate the risk. Unpatched systems remain vulnerable to remote attack.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.