CVE-2025-21274

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 59

Summary

CVE-2025-21274 is a newly disclosed vulnerability affecting Windows Event Tracing, a diagnostic tool in the operating system. An attacker can exploit this Denial of Service (DoS) vulnerability by sending specially crafted events to the Event Tracing Log session, causing the service to crash and become unresponsive. This issue may impact system availability and could potentially be used in conjunction with other attacks to gain unauthorized access to affected systems. Microsoft recommends implementing security best practices, such as applying security updates, configuring firewalls, and limiting access to Event Tracing for mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share