CVE-2025-21321

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 532

Summary

CVE-2025-21321 is a newly disclosed vulnerability affecting the Windows Kernel that permits an attacker to disclose memory information. This issue can potentially expose sensitive data, including kernel addresses and other system information, which could be utilized in further attacks. An attacker could exploit this vulnerability through a specially crafted application or maliciously crafted file, gaining unauthorized access to this information. Microsoft is working on a patch to address this vulnerability, and users are advised to apply it as soon as it becomes available to mitigate the risk. In the meantime, implementing security best practices, such as running up-to-date antivirus software and limiting user privileges, can help reduce the risk of a successful attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Windows Server 2022

Affected Vendors

  • Microsoft