ZeroHour

CVE-2025-21334

KEVmass1· 2 reads

Use-After-Free Privilege Escalation in Windows Hyper-V NT Kernel Integration VSP

CISA: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p74
Published
()
KEV added
AI analysis

CVE-2025-21334 is a use-after-free vulnerability (CWE-416) in the Microsoft Windows Hyper-V NT Kernel Integration VSP, the component that integrates the Hyper-V virtualization stack with the Windows NT kernel, and it is rated 7.8 (high) with a local, low-privilege attack vector. A local attacker who already has low-privileged access to an affected machine can trigger the flaw to reuse freed kernel memory and execute code with elevated, kernel-level privileges, gaining full control of the host as an additional step after an initial compromise. The flaw affects Windows 10 21H2 and 22H2, Windows 11 22H2, 23H2 and 24H2, Windows Server 2022 23H2, and Windows Server 2025, spanning much of Microsoft's currently supported client and server line. It was a zero-day: Microsoft patched it in the January 2025 Patch Tuesday release as one of three actively exploited flaws, and CISA added it to the Known Exploited Vulnerabilities catalog on January 14, 2025. Ransomware use is listed as unknown, and with a local attack vector the flaw is most plausibly used for post-compromise privilege escalation rather than initial access.

What to do: Apply Microsoft's January 2025 security updates (Patch Tuesday, January 14, 2025) to all affected Windows 10/11 clients and Windows Server hosts, prioritizing Hyper-V hosts and multi-user systems where local privilege escalation has the greatest impact. No workaround is listed, so any system still missing the patch should be treated as vulnerable; if patching is delayed, follow vendor mitigation guidance per the CISA KEV entry (added 2025-01-14) and inventory systems running Hyper-V or Windows virtualization features.

Affected
Microsoft Windows 1021H2
Microsoft Windows 1022H2
Microsoft Windows 1122H2
Microsoft Windows 1123H2
Microsoft Windows 1124H2
Microsoft Windows Server 202223H2
Microsoft Windows Server 20252025
Estimated exposure
masshundreds of millions of Windows installations (the listed releases cover most of the current Windows 10/11 client base and current Windows Server releases) — The affected Windows 10/11 releases make up most of the global Windows install base (over a billion Windows devices by public estimates) and Windows Server 2022/2025 are current server releases, so affected installations plausibly number…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2022 23h2, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news