← Back to browse · API

CVE-2025-21335

Severity
HIGH
CVSS
7.8
EPSS
0.01363
Risk score
56.68
CISA KEV
Yes
PoC
No
Published
2025-01-14
Modified
2025-01-14
First seen
2026-08-07
Aliases
EUVD-2025-2400, GHSA-6P26-7GX2-V5M2
Products
Microsoft:Windows, Microsoft:Windows 10 Version 21H2 10.0.19044.0 <10.0.19044.5371, Microsoft:Windows 10 Version 22H2 10.0.19045.0 <10.0.19045.5371, Microsoft:Windows 11 Version 23H2 10.0.22631.0 <10.0.22631.4751, Microsoft:Windows 11 Version 24H2 10.0.26100.0 <10.0.26100.2894, Microsoft:Windows 11 version 22H2 10.0.22621.0 <10.0.22621.4751, Microsoft:Windows 11 version 22H3 10.0.22631.0 <10.0.22631.4751, Microsoft:Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 <10.0.25398.1369, Microsoft:Windows Server 2025 (Server Core installation) 10.0.26100.0 <10.0.26100.2894, Microsoft:Windows Server 2025 10.0.26100.0 <10.0.26100.2894
Sources
cisa.gov CVE-2025-21335
euvd EUVD-2025-2400

Description

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

References