CVE-2025-21324
CVSS 3.1 Score 6.6 of 10 (medium)
Details
Summary
CVE-2025-21324 is a newly disclosed vulnerability affecting Windows Digital Media. This elevation of privilege issue allows an attacker to manipulate specially crafted media files, potentially granting them system-level access on vulnerable systems. Successful exploitation could lead to the installation of malware or unauthorized system modifications. This vulnerability poses a serious threat to Windows users and requires immediate attention, with Microsoft releasing a patch to address the issue. It is crucial for organizations and individuals to apply the patch promptly to protect their systems from potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008
- Windows Server 2022
Affected Vendors
- Microsoft