CVE-2025-21340

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 284

Summary

CVE-2025-21340 is a security vulnerability affecting Windows Virtualization-Based Security (VBS). This issue permits bypassing VBS security features, potentially exposing the host system to threats. An attacker could leverage this vulnerability to execute code within the virtual machine, gaining unauthorized access to the host system. The consequences of an exploit could range from data theft to system compromise. Microsoft has released a patch to address this vulnerability, and it is recommended that users apply the update as soon as possible to mitigate risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share