CVE-2025-21281

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 416

Summary

CVE-2025-21281 refers to a Microsoft COM for Windows Elevation of Privilege vulnerability. Maliciously crafted files or web pages can exploit this flaw, leading an attacker to gain elevated system privileges. Successful exploitation allows the attacker to install programs, modify data, or create new accounts with full administrator rights. This issue poses a significant threat to Windows systems, potentially enabling further attacks and system compromise. Microsoft strongly advises installing the available patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share