CVE-2025-21350

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Feb 11, 2025
CWE ID 20

Summary

CVE-2025-21350 is a recently disclosed vulnerability affecting Windows Kerberos, an authentication protocol used to verify the identity of users and services on a network. This issue permits an attacker to cause a denial-of-service condition by exploiting a weakness in the way the Kerberos protocol handles certain types of requests. The vulnerability could potentially lead to a server becoming overwhelmed with excessive authentication attempts, rendering it unresponsive to legitimate traffic. Microsoft has released a patch to address the issue, and it is strongly recommended that all affected systems be updated promptly to mitigate the risk. Failure to do so could result in extended downtime and potential data loss.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft