HIGH

CVE-2025-21333

Microsoft Windows 10 21h2 2025-01-14 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

Summary dbcve.org

This is a local elevation of privilege vulnerability in Windows Hyper-V's NT Kernel Integration Virtual Service Provider (VSP). The vulnerability allows an authenticated local attacker to gain elevated privileges on the affected system through the kernel integration component used for host-guest communication.

Mitigation

Apply the Microsoft security update for CVE-2025-21333 via Windows Update or Microsoft Update Catalog. For Hyper-V environments, ensure both the host and guest integration services are patched.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow

EPSS Score

9.99%
Probability of exploitation in next 30 days
95.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE