CVE-2025-21391

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 12, 2025
CWE ID 59

Summary

CVE-2025-21391 is a newly disclosed Windows vulnerability that allows an attacker to elevate privileges through the Storage Spaces feature. By exploiting this Storage Elevation of Privilege vulnerability, an attacker can gain administrative access to a system, potentially leading to serious data theft or system compromise. This issue affects Windows Server 2012 R2 and later versions, and Microsoft has released a security update to address it. Users are strongly encouraged to install the patch as soon as possible to protect their systems from potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft