CVE-2025-21372
Published: 14 January 2025
Description
Microsoft Brokering File System Elevation of Privilege Vulnerability
Security Summary
CVE-2025-21372 is an Elevation of Privilege vulnerability affecting the Microsoft Brokering File System. Published on January 14, 2025, it carries a CVSS v3.1 base score of 7.8 (AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) and is linked to CWE-416, with additional NVD-CWE-noinfo classification.
A local attacker with low privileges can exploit this vulnerability. Exploitation requires high attack complexity and local access vector but no user interaction. Successful exploitation enables privilege escalation, yielding high impacts on confidentiality, integrity, and availability within a changed scope.
Microsoft's Security Response Center provides mitigation details and patches via their update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21372.
Details
- CWE(s)