VDB
CVE-2025-21180
CVE-2025-21180
PUBLISHED
CVSS 8.699999809265137 HIGH
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft Windows Server, Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows, Microsoft Windows Server 2022 und Microsoft Windows 11 ausnutzen, um beliebigen Programmcode auszuführen, seine Rechte zu erweitern, zu spoofen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen oder einen Denial of Service auszulösen .
EPSS 0.93% · 57.9th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.93%
57.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Windows Server 2022 <10.0.20348.3270 | |
| Hitachi | Hitachi Virtual Storage Platform | |
| Microsoft | Microsoft Windows Server 2012 R2 <6.3.9600.22470 | |
| Microsoft | Microsoft Windows Server 2012 <6.2.9200.25368 | |
| Microsoft | Microsoft Windows Server 2019 <10.0.17763.7009 | |
| Microsoft | Microsoft Windows 10 <10.0.10240.20947 | |
| Microsoft | Microsoft Windows Server 2016 <10.0.14393.7876 |
Timeline
- Mar 11, 2025 Coalition ESS Score
- Mar 11, 2025 CVE Published
- Mar 12, 2025 EPSS Score
- Mar 12, 2025 Coalition ESS Score
- Mar 13, 2025 Coalition ESS Score
- Mar 24, 2025 Coalition ESS Score
- Mar 26, 2025 EPSS Score
- Apr 8, 2025 EPSS Score
- Apr 21, 2025 PoC Published
- Apr 22, 2025 EPSS Score
- May 6, 2025 EPSS Score
- May 13, 2025 PoC Published
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-0537.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0537 advisory
- https://msrc.microsoft.com/update-guide/ advisory
- https://github.com/0x6rss/CVE-2025-24071_PoC exploit
- https://www.hitachi.com/products/it/storage-solutions/sec_info/2025/04.html advisory