CVE-2025-21436

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 7, 2025
CWE ID 416

Summary

CVE-2025-21436 is a newly disclosed vulnerability that can lead to memory corruption. This issue arises when two IOCTL (Input/Output Control) calls are initiated concurrently from separate threads to create processes. The memory corruption can potentially be exploited by attackers to gain unauthorized access or execute arbitrary code. This vulnerability can pose a significant risk to systems that support multiple threads and require the use of IOCTL calls to create processes. It is recommended that affected systems be patched as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share