CVE-2025-21231
Published: 14 January 2025
Description
IP Helper Denial of Service Vulnerability
Security Summary
CVE-2025-21231, published on 2025-01-14, is an IP Helper Denial of Service vulnerability with a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). It is associated with CWE-400 (Uncontrolled Resource Consumption) and NVD-CWE-noinfo. The vulnerability affects the IP Helper component in Microsoft Windows systems, as indicated by the Microsoft Security Response Center reference.
An unauthenticated attacker (PR:N) can exploit the vulnerability remotely over the network (AV:N) with low attack complexity (AC:L) and without requiring user interaction (UI:N). Successful exploitation results in high impact to availability (A:H) with no impact to confidentiality or integrity, enabling a denial of service condition such as service crashes or resource exhaustion.
Microsoft has published an update guide addressing this vulnerability, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21231, which provides details on patches and mitigation steps.
Details
- CWE(s)