CVE-2025-21311: Windows NTLM V1 Elevation of Privilege Vulnerability
Published Jan 14, 2025
·Updated
Windows NTLM V1 Elevation of Privilege Vulnerability
Affected Software
8 affected componentsFixes available
Microsoft Windows Server 2025
Microsoft Windows Server 2025
Microsoft Windows Server 2022, 23H2 Edition
Microsoft Windows 11=24H2
Microsoft Windows 11=24H2
Microsoft Windows 11 24h2<10.0.26100.2894
Microsoft Windows Server 2022 23h2<10.0.25398.1369
Microsoft Windows Server 2025<10.0.26100.2894
Remediation
Event History
Jan 14, 2025
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverity
News Published
via Dark Reading·10:56 PM
News Published
via Dark Reading·11:00 PM
Jan 15, 2025
News Published
via The Register·01:33 AM
News Published
via The Register·01:36 AM
Jan 20, 2025
Known Exploited
10:24 AM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-21311?
CVE-2025-21311 has a severity rating of critical due to its potential for elevation of privilege on affected systems.
2
How do I fix CVE-2025-21311?
To fix CVE-2025-21311, ensure that you apply the patches provided in Microsoft's update guidance.
3
What products are affected by CVE-2025-21311?
CVE-2025-21311 affects Microsoft Windows Server 2025 and Windows 11 (24H2), among other related products.
4
What impact does CVE-2025-21311 have on my system?
CVE-2025-21311 can allow an attacker to elevate privileges, potentially compromising the integrity of the entire system.
5
Is CVE-2025-21311 a zero-day vulnerability?
CVE-2025-21311 is not classified as a zero-day vulnerability since patches are available to mitigate the risk.