CVE-2025-21198
Published: 11 February 2025
Description
Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
Security Summary
CVE-2025-21198 is a remote code execution vulnerability affecting Microsoft High Performance Compute (HPC) Pack. Published on 2025-02-11, it carries a CVSS v3.1 base score of 9.0, reflecting its critical severity with vector AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The issue is linked to CWE-306 (Missing Authentication for Critical Function) and lacks additional CWE details from NVD.
Exploitation requires an attacker to have low privileges (PR:L) on an adjacent network (AV:A) with low attack complexity (AC:L) and no user interaction (UI:N). Successful exploitation allows scope change (S:C), granting high-impact remote code execution with full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H).
The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21198 provides details on patches and mitigation guidance.
Details
- CWE(s)