CVE-2025-21257
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-21257 is a vulnerability affecting the Windows WLAN AutoConfig Service. This issue allows an attacker to disclose sensitive information, potentially leading to unauthorized access or further exploitation. The WLAN AutoConfig Service is responsible for managing wireless network profiles, and an attacker can trigger the disclosure of information through a specially crafted network packet. The vulnerability poses a serious risk to organizations and individuals using affected Windows systems, and it is recommended that users apply the available Microsoft security patch as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.