CVE-2025-21358
Published: 11 February 2025
Description
Windows Core Messaging Elevation of Privileges Vulnerability
Security Summary
CVE-2025-21358 is a Windows Core Messaging Elevation of Privileges Vulnerability, published on 2025-02-11. It affects the Core Messaging component in Windows operating systems and is associated with CWE-822 (Untrusted Pointer Dereference) along with NVD-CWE-noinfo. The vulnerability has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact with local access.
A local attacker with low privileges (PR:L) can exploit this vulnerability through low-complexity attacks requiring no user interaction (UI:N). Successful exploitation enables high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), allowing the attacker to elevate privileges, potentially gaining full system control within the unchanged security scope (S:U).
Microsoft's Security Response Center provides update guidance and mitigation details for CVE-2025-21358 at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21358.
Details
- CWE(s)