CVE-2025-21391: Microsoft Windows Storage Link Following Vulnerability
Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.
Other sources
Windows Storage Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7785Patch KB5052006 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20915Patch KB5052040 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.3194Fixed in 10.0.26100.3107Patch KB5052105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4890Patch KB5051989 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5487Patch KB5051974 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4890Patch KB5051989 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1425Patch KB5051980 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5487Patch KB5051974 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3207Fixed in 10.0.20348.3148Patch KB5052106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6893Patch KB5052000
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-21391?
CVE-2025-21391 is classified as a privilege escalation vulnerability.
How do I fix CVE-2025-21391?
To fix CVE-2025-21391, apply the relevant security patches provided by Microsoft for the affected products.
What products are affected by CVE-2025-21391?
CVE-2025-21391 affects various Microsoft products including Windows Server 2016, Windows 10 (multiple versions), and Windows 11.
Can CVE-2025-21391 lead to data loss?
Yes, CVE-2025-21391 could allow an attacker to delete critical data, resulting in data loss.
Is there a known exploit for CVE-2025-21391?
As of now, there is no publicly disclosed exploit specifically targeting CVE-2025-21391.