CVE-2025-21257

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 125

Summary

CVE-2025-21257 is a vulnerability affecting the Windows WLAN AutoConfig Service. This issue allows an attacker to disclose sensitive information, potentially leading to unauthorized access or further exploitation. The WLAN AutoConfig Service is responsible for managing wireless network profiles, and an attacker can trigger the disclosure of information through a specially crafted network packet. The vulnerability poses a serious risk to organizations and individuals using affected Windows systems, and it is recommended that users apply the available Microsoft security patch as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share