CVE-2025-21382

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 190
CWE ID 122

Summary

CVE-2025-21382 is a newly disclosed elevation of privilege vulnerability affecting the Windows Graphics Component. Successful exploitation of this vulnerability could allow an attacker to gain administrative privileges on an affected system. This issue can be exploited remotely through specially crafted graphics files, posing a significant threat to organizations and individuals using unpatched Windows systems. Mitigation measures include applying the latest software updates and implementing network security solutions to block malicious content. Organizations are advised to prioritize patching to minimize potential attack surface and protect against potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Windows Server 2022

Affected Vendors

  • Microsoft