CVE-2025-21299
Published: 14 January 2025
Description
Windows Kerberos Security Feature Bypass Vulnerability
Security Summary
CVE-2025-21299 is a Windows Kerberos Security Feature Bypass Vulnerability affecting the Kerberos authentication component in Microsoft Windows operating systems. Published on 2025-01-14, it carries a CVSS v3.1 base score of 7.1 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) and is associated with CWE-922 (Omission of Security-relevant Information) and NVD-CWE-noinfo.
A local attacker with low privileges can exploit this vulnerability through low-complexity means without user interaction. Exploitation enables high-impact confidentiality and integrity violations, allowing bypass of Kerberos security features while maintaining unchanged scope and no availability disruption.
Microsoft's Security Response Center provides an update guide with vulnerability details and mitigation recommendations at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21299.
Details
- CWE(s)