CVE-2025-21299

Published Jan 14, 2025

Last updated 3 months ago

CVSS high 7.1
Windows Kerberos

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-21299 is a security feature bypass vulnerability affecting Windows Kerberos. The vulnerability stems from an error in how the system handles maliciously crafted requests. Successful exploitation of this vulnerability could allow an attacker to bypass security features. It affects multiple versions of Windows, including Windows 10, Windows Server 2019, Windows Server 2022, and others.

Description
Windows Kerberos Security Feature Bypass Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-922
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations