Junglewise Threat Intelligence

CVE-2025-21333: Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability

CVE-2025-21333 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-01-14

Technologies: Microsoft Windows Server 2025, Microsoft Windows, Microsoft Windows Server 2022 23h2, Microsoft Windows 11 24h2, Microsoft Windows 11 22h2, Microsoft Windows 10 22h2, Microsoft Windows 10 21h2, Microsoft Windows 11 23h2. Vendors: Microsoft.

Executive brief

A heap-based buffer overflow vulnerability in the Microsoft Windows Hyper-V NT Kernel Integration VSP allows a local attacker to escalate privileges to SYSTEM level. The flaw is actively exploited in the wild and affects multiple versions of Windows 10, 11, and Windows Server.

Affected products

  • Microsoft Windows 10 21H2 up to (excluding) 10.0.19044.5371
  • Microsoft Windows 10 22H2 up to (excluding) 10.0.19045.5371
  • Microsoft Windows 11 22H2 up to (excluding) 10.0.22621.4751
  • Microsoft Windows 11 23H2 up to (excluding) 10.0.22631.4751
  • Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.2894
  • Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1369
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.2894

Timeline

  • 2025-01-14: disclosed
  • 2025-01-14: patched
  • 2025-01-14: kev added: Added to CISA KEV catalog
  • 2025-01-14: exploited: Reported as exploited in the wild at time of publication

Related threats