CVE-2025-21322 is an Elevation of Privilege vulnerability affecting Microsoft PC Manager. With a CVSS score of 7.8 (HIGH), it allows a local attacker to gain elevated privileges with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness. Microsoft has addressed this flaw in their February 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.15.4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:pc_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.