CVE-2025-21315

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 416

Summary

CVE-2025-21315 is a critical file system elevation of privilege vulnerability affecting Microsoft's Brokering Service. This issue arises due to improper access control, enabling an attacker to exploit it and gain administrative privileges. Successful exploitation could lead to significant damage, including data theft or system takeover. Microsoft strongly advises users to install the available security patch to mitigate this risk. Unpatched systems remain vulnerable and are at high risk of attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 11
  • Windows Server 2022

Affected Vendors

  • Microsoft