CVE-2025-21300
Published: 14 January 2025
Description
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
Security Summary
CVE-2025-21300 is a Denial of Service vulnerability in the Windows Universal Plug and Play (UPnP) Device Host component. Published on 2025-01-14, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is associated with CWE-400 (Uncontrolled Resource Consumption), though additional CWE details are unavailable from NVD.
The vulnerability can be exploited by remote attackers with network access, requiring no authentication privileges, low attack complexity, and no user interaction. Exploitation results in high availability impact, enabling denial of service through resource exhaustion or disruption of the UPnP Device Host service.
Microsoft's Security Response Center update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21300 provides details on affected versions and recommended mitigations or patches.
Details
- CWE(s)