CVE-2025-21298
massUse-After-Free RCE in Windows OLE (CVE-2025-21298)
CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days.
What to do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges.
| microsoft Windows 10 | 1507 |
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows Server 2008 | all editions listed by Microsoft CPE data (no finer version granularity provided) |
| microsoft Windows Server 2012 | all editions listed by Microsoft CPE data (no finer version granularity provided) |
| microsoft Windows Server 2016 | all editions listed by Microsoft CPE data (no finer version granularity provided) |
| microsoft Windows Server 2019 | all editions listed by Microsoft CPE data (no finer version granularity provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows OLE Remote Code Execution Vulnerability
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H