Junglewise Threat Intelligence

CVE-2025-21334: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

CVE-2025-21334 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-01-14

Technologies: Microsoft Windows Server 2025, Microsoft Windows, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 23H2, Microsoft Windows Server 2022 23h2, Microsoft Windows 10 Version 22H2, Microsoft Windows 10 Version 21H2. Vendors: Microsoft.

Executive brief

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability. A local attacker can exploit this flaw to escalate privileges to SYSTEM level. This vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 10 Version 21H2 up to (excluding) 10.0.19044.5371
  • Microsoft Windows 10 Version 22H2 up to (excluding) 10.0.19045.5371
  • Microsoft Windows 11 Version 22H2 up to (excluding) 10.0.22621.4751
  • Microsoft Windows 11 Version 23H2 up to (excluding) 10.0.22631.4751
  • Microsoft Windows 11 Version 24H2 up to (excluding) 10.0.26100.2894
  • Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1369
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.2894

Timeline

  • 2025-01-14: disclosed
  • 2025-01-14: patched
  • 2025-01-14: kev added: Added to CISA KEV catalog due to active exploitation.
  • 2025-01-14: exploited

Related threats