ZeroHour

CVE-2025-21391

KEVmass1

Actively Exploited Windows Storage Link-Following Elevation of Privilege (CVE-2025-21391)

CISA: Microsoft Windows Storage Link Following Vulnerability

CVSS 3.1
7.1 high
EPSS
2%p82
Published
()
KEV added
AI analysis

CVE-2025-21391 is a link-following (CWE-59) elevation of privilege flaw in the Windows Storage service: a local, low-privileged attacker can plant or abuse a junction or symbolic link that the service follows, redirecting its privileged file operations. The CVSS scoring (high integrity and availability impact, none for confidentiality) indicates that successful exploitation lets the attacker modify or delete files system-wide at elevated privilege, potentially including files needed for the system to function. The attack is local (AV:L), requires no user interaction, and only needs limited rights on the target machine, so risk is greatest on multi-user systems, hosts exposed to remote access tools, and endpoints that are already partially compromised. All supported Windows client branches (Windows 10 1507 through 22H2 and Windows 11 22H2 through 24H2) and Windows Server 2016, 2019, 2022, and 2022 23H2 are in scope. Microsoft fixed it as one of two actively exploited zero-days in February 2025 Patch Tuesday, and CISA added it to the KEV catalog on 2025-02-11 with ransomware use listed as unknown; no public PoC is known, but in-the-wild exploitation is confirmed.

What to do: Apply the February 2025 Windows cumulative security updates (released February 11, 2025) to all Windows 10/11 and Windows Server hosts, prioritizing workstations, terminal/RDP servers, and systems that allow interactive logons. If immediate patching is not possible, apply Microsoft's interim mitigation by restricting access to the Windows Storage service via its service security descriptor so only administrators can interact with it. Look for unexplained file deletions or modifications in system directories, and ensure this CVE is included in KEV remediation tracking, as CISA's listing obligates federal agencies to apply vendor mitigations by the published due date.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2
microsoft Windows 1122H2, 23H2, 24H2
microsoft Windows Server 2016all supported releases
microsoft Windows Server 2019all supported releases
microsoft Windows Server 2022all supported releases
microsoft Windows Server 2022 23H223H2
Estimated exposure
mass≈1 billion Windows devices (Windows installed base; every supported Windows 10/11/Server branch is listed as affected) — Windows runs on roughly 1.4 billion devices worldwide and the CPE data lists every currently supported Windows 10, Windows 11, and Windows Server release, so the exposed population is effectively the entire installed base, though practical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Storage Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news