CVE-2025-21335
KEVmass1Use-After-Free Elevation of Privilege in Windows Hyper-V NT Kernel Integration VSP
CISA: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
CVE-2025-21335 is a use-after-free (CWE-416) in the Windows Hyper-V NT Kernel Integration VSP, a Hyper-V virtualization service provider component integrated with the Windows NT kernel. A local attacker with limited privileges can trigger it by causing memory used by the VSP to be freed while still in use, and no user interaction is required. Successful exploitation elevates the attacker's privileges to the highest (SYSTEM/kernel) level on the affected machine, yielding full control of that host. The flaw affects the listed Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 and Windows Server 2025 releases, and is most relevant to Hyper-V hosts and machines with virtualization features enabled. It is being actively exploited in the wild (added to CISA's KEV on 2025-01-14), was patched in Microsoft's January 14, 2025 security updates, and ransomware use has not yet been confirmed.
What to do: Apply Microsoft's January 2025 cumulative security updates (released January 14, 2025) to all affected Windows 10/11 and Windows Server systems immediately, prioritizing Hyper-V hosts and multi-user servers where untrusted local accounts exist. Verify each host received the update via Windows Update or patch reporting, review systems for indicators of local privilege escalation, and note that CISA KEV requires applying vendor mitigations or discontinuing use of affected configurations if patches are unavailable.
| Microsoft Windows 10 | 21H2, 22H2 |
| Microsoft Windows 11 | 22H2, 23H2, 24H2 |
| Microsoft Windows Server 2022 | 23H2 |
| Microsoft Windows Server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2022 23h2, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H