CVE-2025-21174 is a high-severity vulnerability affecting Windows Server versions 2012 through 2025, allowing an unauthenticated attacker to cause a denial of service through uncontrolled resource consumption in the Standards-Based Storage Management Service. With a CVSS score of 7.5, this network-exploitable flaw requires no user interaction and has a high impact on availability. While not currently in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, its high FAUCET Risk Score of 97/100 and mention in a BleepingComputer article indicate significant concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
< 10.0.14393.7969CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* | ||
< 10.0.17763.7136CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* | ||
< 10.0.20348.3453CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* | ||
< 10.0.26100.3775CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.