CVE-2025-21333 is a critical Elevation of Privilege vulnerability affecting Windows Hyper-V NT Kernel Integration VSP across various Windows 10, 11, and Server 2022/2025 versions. With a CVSS score of 7.8 (HIGH) and a FAUCET Risk Score of 100/100, this vulnerability allows a local, low-privileged attacker to achieve high impact on confidentiality, integrity, and availability without user interaction. The vulnerability is actively exploited in the wild, listed in CISA's KEV catalog, and public Proof-of-Concept (POC) exploit code is available, as evidenced by community discussions and an ExploitDB entry. This CVE has garnered significant community attention and media coverage, indicating its widespread recognition and potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.19044.5371CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.19045.5371CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:* | ||
< 10.0.22621.4751CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22631.4751CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* | ||
< 10.0.26100.2894CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.