CVE-2025-21367
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-21367 is a newly disclosed Windows vulnerability that affects the Win32 Kernel Subsystem. This elevation of privilege issue grants attackers the ability to escalate their privileges, potentially allowing them to gain system-level access on affected systems. Successful exploitation could result in significant harm, including data theft, unauthorized system modifications, or the installation of malware. Microsoft has not yet released a patch for this vulnerability, leaving affected systems at risk until a fix becomes available. Users are strongly encouraged to apply security best practices, such as applying software updates in a timely manner and implementing robust access control policies, to mitigate risk in the interim.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.