CVE-2025-21299

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 922

Summary

CVE-2025-21299 is a recently disclosed vulnerability that affects the Windows Kerberos authentication protocol. This security flaw permits an attacker to bypass Kerberos security features, potentially gaining unauthorized access to sensitive data or systems. The vulnerability arises due to an issue in the way Windows handles certain authentication requests, allowing an adversary to manipulate the response and evade security checks. Mitigation includes applying Microsoft's recommended patch and implementing strong password policies, as well as enabling multi-factor authentication where possible. Failure to address this vulnerability may result in significant data breaches or unauthorized system access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Windows Server 2022

Affected Vendors

  • Microsoft