ZeroHour

CVE-2025-21298

mass

Use-After-Free RCE in Windows OLE (CVE-2025-21298)

CVSS 3.1
9.8 critical
EPSS
81%p100
Published
()
Modified
AI analysis

CVE-2025-21298 is a use-after-free (CWE-416) vulnerability in the Windows OLE (Object Linking and Embedding) component that permits remote code execution. According to the published CVSS vector, it is network-exploitable without privileges or user interaction, triggered when the system processes maliciously crafted OLE content. A successful attacker gains arbitrary code execution in the context of the affected process, with high impact on confidentiality, integrity, and availability. The flaw affects nearly the entire supported Windows estate — Windows 10 1507 through 22H2, Windows 11 22H2 through 24H2, and Windows Server 2008 through 2019. As of the January 2025 Patch Tuesday release there is no known public proof-of-concept or confirmed in-the-wild exploitation, but the EPSS score of 80.9% (100th percentile) indicates a very high probability of exploitation within 30 days.

What to do: Apply Microsoft's January 2025 Windows cumulative security updates to all affected Windows 10/11 and Windows Server hosts immediately, prioritizing internet-facing and server systems given the network-exploitable, critical rating. Verify via patch-reporting tools that the OLE update is present on each host; no vendor mitigations were noted in the available data, so updating is the primary defense. Although no exploitation is confirmed yet, the 80.9% EPSS score argues for completing remediation before a PoC or in-the-wild exploitation emerges.

Affected
microsoft Windows 101507
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1122H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows Server 2008all editions listed by Microsoft CPE data (no finer version granularity provided)
microsoft Windows Server 2012all editions listed by Microsoft CPE data (no finer version granularity provided)
microsoft Windows Server 2016all editions listed by Microsoft CPE data (no finer version granularity provided)
microsoft Windows Server 2019all editions listed by Microsoft CPE data (no finer version granularity provided)
Estimated exposure
mass≈1 billion+ Windows installations (essentially the entire supported Windows client and Server estate) — The affected list spans every supported Windows 10/11 client release and Windows Server 2008 through 2019, and Microsoft's publicly stated Windows installed base is on the order of 1.4 billion devices, so effectively all supported Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows OLE Remote Code Execution Vulnerability

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news