CVE-2025-21333: Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
Other sources
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.2894Patch KB5050009 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5371Patch KB5049981 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1369Patch KB5049984 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4751Patch KB5050021 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4751Patch KB5050021 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5371Patch KB5049981
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-21333?
CVE-2025-21333 is classified as an elevation of privilege vulnerability that allows local attackers to gain SYSTEM privileges.
How do I fix CVE-2025-21333?
To mitigate CVE-2025-21333, apply the latest patches provided by Microsoft for the affected versions of Windows.
Which versions of Windows are affected by CVE-2025-21333?
CVE-2025-21333 affects Microsoft Windows Server 2025, Windows 11 versions 22H2, 23H2, and 24H2, and Windows 10 versions 21H2 and 22H2.
What type of vulnerability is CVE-2025-21333?
CVE-2025-21333 is a heap-based buffer overflow vulnerability in the Microsoft Windows Hyper-V NT Kernel Integration.
Can CVE-2025-21333 be exploited remotely?
No, CVE-2025-21333 requires local access for exploitation, thus posing a risk primarily to local users.