CVE-2025-21335: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
Other sources
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.2894Patch KB5050009 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1369Patch KB5049984 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4751Patch KB5050021 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5371Patch KB5049981 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4751Patch KB5050021 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5371Patch KB5049981
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-21335?
CVE-2025-21335 is considered a critical vulnerability that can lead to elevation of privilege on affected systems.
How do I fix CVE-2025-21335?
To fix CVE-2025-21335, you should apply the latest security updates provided by Microsoft, specifically KB5050009 or KB5050021 depending on your operating system.
Which versions of Windows are affected by CVE-2025-21335?
CVE-2025-21335 affects Microsoft Windows Server 2025, Windows 10 version 21H2 and 22H2, and Windows 11 versions 22H2, 23H2, and 24H2.
Can CVE-2025-21335 be exploited remotely?
CVE-2025-21335 cannot be exploited remotely; it requires local access to the system to take advantage of the vulnerability.
What are the potential consequences of CVE-2025-21335?
Exploitation of CVE-2025-21335 can allow an attacker to gain SYSTEM privileges, potentially compromising the security of the entire system.