ZeroHour

CVE-2025-21335

KEVmass1

Use-After-Free Elevation of Privilege in Windows Hyper-V NT Kernel Integration VSP

CISA: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p71
Published
()
KEV added
AI analysis

CVE-2025-21335 is a use-after-free (CWE-416) in the Windows Hyper-V NT Kernel Integration VSP, a Hyper-V virtualization service provider component integrated with the Windows NT kernel. A local attacker with limited privileges can trigger it by causing memory used by the VSP to be freed while still in use, and no user interaction is required. Successful exploitation elevates the attacker's privileges to the highest (SYSTEM/kernel) level on the affected machine, yielding full control of that host. The flaw affects the listed Windows 10 21H2/22H2, Windows 11 22H2/23H2/24H2, Windows Server 2022 23H2 and Windows Server 2025 releases, and is most relevant to Hyper-V hosts and machines with virtualization features enabled. It is being actively exploited in the wild (added to CISA's KEV on 2025-01-14), was patched in Microsoft's January 14, 2025 security updates, and ransomware use has not yet been confirmed.

What to do: Apply Microsoft's January 2025 cumulative security updates (released January 14, 2025) to all affected Windows 10/11 and Windows Server systems immediately, prioritizing Hyper-V hosts and multi-user servers where untrusted local accounts exist. Verify each host received the update via Windows Update or patch reporting, review systems for indicators of local privilege escalation, and note that CISA KEV requires applying vendor mitigations or discontinuing use of affected configurations if patches are unavailable.

Affected
Microsoft Windows 1021H2, 22H2
Microsoft Windows 1122H2, 23H2, 24H2
Microsoft Windows Server 202223H2
Microsoft Windows Server 2025
Estimated exposure
masstens of millions of Windows endpoints and servers on the affected builds (subset with Hyper-V/virtualization components active) — Windows 10/11 and Windows Server hold dominant desktop and server OS market share and the named builds are widely deployed, so even restricted to machines running the Hyper-V integration VSP the affected population plausibly exceeds one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2022 23h2, windows server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news