CVE-2025-21391
Published: 11 February 2025
Description
Windows Storage Elevation of Privilege Vulnerability
Security Summary
CVE-2025-21391 is a Windows Storage Elevation of Privilege Vulnerability affecting the Windows Storage component in Microsoft Windows operating systems. Published on 2025-02-11, it has a CVSS v3.1 base score of 7.1 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) and is associated with CWE-59.
The vulnerability can be exploited by a local attacker who already possesses low-level privileges on the target system. Exploitation requires low complexity and no user interaction, enabling the attacker to elevate privileges with high impacts on system integrity and availability, though confidentiality remains unaffected.
Microsoft's update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21391 provides details on available security updates to address the issue. The vulnerability is also listed in CISA's Known Exploited Vulnerabilities Catalog at https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21391, indicating real-world exploitation and requiring mitigation by federal civilian executive branch agencies.
Details
- CWE(s)
- KEV Date Added
- 11 February 2025