CVE-2025-21293
Published: 14 January 2025
Description
Active Directory Domain Services Elevation of Privilege Vulnerability
Security Summary
CVE-2025-21293 is an elevation of privilege vulnerability in Active Directory Domain Services, published on 2025-01-14T18:15:51.110. It affects Microsoft's Active Directory Domain Services component, with a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The issue is associated with CWE-284 (Improper Access Control) and lacks additional NVD CWE details.
The vulnerability can be exploited by a low-privileged authenticated user with network access to the target system. Exploitation requires low complexity and no user interaction, allowing the attacker to elevate privileges with high impacts on confidentiality, integrity, and availability within the unchanged security scope.
Microsoft's Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21293 provides details on patches and mitigation guidance.
Details
- CWE(s)