CVE-2025-21391
KEVmass1Actively Exploited Windows Storage Link-Following Elevation of Privilege (CVE-2025-21391)
CISA: Microsoft Windows Storage Link Following Vulnerability
CVE-2025-21391 is a link-following (CWE-59) elevation of privilege flaw in the Windows Storage service: a local, low-privileged attacker can plant or abuse a junction or symbolic link that the service follows, redirecting its privileged file operations. The CVSS scoring (high integrity and availability impact, none for confidentiality) indicates that successful exploitation lets the attacker modify or delete files system-wide at elevated privilege, potentially including files needed for the system to function. The attack is local (AV:L), requires no user interaction, and only needs limited rights on the target machine, so risk is greatest on multi-user systems, hosts exposed to remote access tools, and endpoints that are already partially compromised. All supported Windows client branches (Windows 10 1507 through 22H2 and Windows 11 22H2 through 24H2) and Windows Server 2016, 2019, 2022, and 2022 23H2 are in scope. Microsoft fixed it as one of two actively exploited zero-days in February 2025 Patch Tuesday, and CISA added it to the KEV catalog on 2025-02-11 with ransomware use listed as unknown; no public PoC is known, but in-the-wild exploitation is confirmed.
What to do: Apply the February 2025 Windows cumulative security updates (released February 11, 2025) to all Windows 10/11 and Windows Server hosts, prioritizing workstations, terminal/RDP servers, and systems that allow interactive logons. If immediate patching is not possible, apply Microsoft's interim mitigation by restricting access to the Windows Storage service via its service security descriptor so only administrators can interact with it. Look for unexplained file deletions or modifications in system directories, and ensure this CVE is included in KEV remediation tracking, as CISA's listing obligates federal agencies to apply vendor mitigations by the published due date.
| microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 22H2, 23H2, 24H2 |
| microsoft Windows Server 2016 | all supported releases |
| microsoft Windows Server 2019 | all supported releases |
| microsoft Windows Server 2022 | all supported releases |
| microsoft Windows Server 2022 23H2 | 23H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Storage Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H