CVE-2025-21351
Published: 11 February 2025
Description
Windows Active Directory Domain Services API Denial of Service Vulnerability
Security Summary
CVE-2025-21351 is a Denial of Service vulnerability affecting the Windows Active Directory Domain Services API. Published on 2025-02-11, it is classified under CWE-400 (Uncontrolled Resource Consumption) and carries a CVSS v3.1 base score of 7.5, reflecting high availability impact with no confidentiality or integrity effects.
The vulnerability can be exploited by unauthenticated attackers over the network (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N), and without changing scope (S:U). Successful exploitation results in a high-impact denial of service (A:H), potentially disrupting Active Directory Domain Services availability.
Microsoft's update guide provides details on mitigation, available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21351.
Details
- CWE(s)