CVE-2025-21292

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 94

Summary

CVE-2025-21292 is a newly disclosed vulnerability affecting the Windows Search Service. This elevation of privilege issue allows an attacker to gain heightened system access by exploiting a flaw in the way the service handles search queries. Successful exploitation can result in the attacker gaining administrative control over the affected system. Users are strongly urged to install the Microsoft Security Update addressing this issue as soon as possible to mitigate potential risks. This vulnerability can be exploited remotely, making it a significant concern for networks with exposed Windows systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Windows Server 2022

Affected Vendors

  • Microsoft