CVE-2025-21420

Published Feb 11, 2025

Last updated 2 months ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-21420 is an elevation of privilege vulnerability that exists in the Windows Disk Cleanup tool. Successful exploitation could allow an attacker to elevate their privileges to SYSTEM level. As of February 18, 2025, the CVSS v3 score is 7.8, considered High. Microsoft has addressed this vulnerability. It is recommended to apply the necessary security updates to mitigate the risk.

Description
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-59
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2025-21420

    @transilienceai

    8 Mar 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Actively exploited CVE : CVE-2025-21420

    @transilienceai

    3 Mar 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. برای برنامه Windows Disk Cleanup Utility  یا همان (cleanmgr.exe) آسیب پذیری با کد شناسایی CVE-2025-21420 و از نوع privilege escalation منتشر شده است. این آسیب پذیری باعث اجرای کدهای مخرب با دسترسی system از طریق تکنیک DLL sideloading می گردد. https://t.co/Poz3aKY03t https://t.c

    @AmirHossein_sec

    26 Feb 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Reminder; a vulnerability in the Windows Disk Cleanup Tool (cleanmgr.exe) patched by Microsoft (in February 2025 Patch Tuesday, CVE-2025-21420)

    @ikatzsolutions

    23 Feb 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ CVE-2025-21420 : un PoC est dispo. Cette faille critique dans Windows permet une élévation SYSTEM via DLL sideloading. La MAJ est sortie (Patch Tuesday 02/25) : appliquez-la ASAP pour sécuriser vos systèmes ! #cybersécurité #Windows 👇 https://t.co/A2MJ2vyPgL

    @_F2po_

    22 Feb 2025

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️#CVE-2025-21420: PoC available. Critical Windows flaw allows SYSTEM escalation via DLL sideloading. Patch is out (02/25 Patch Tuesday)—apply it ASAP to secure your systems! #cybersecurity #Windows 👇 https://t.co/A2MJ2vyPgL

    @_F2po_

    22 Feb 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-21420: Windows Disk Cleanup Tool Elevation of Privilege Vulnerability https://t.co/NGVhVW1qLk

    @cyber_advising

    21 Feb 2025

    3670 Impressions

    32 Retweets

    90 Likes

    37 Bookmarks

    0 Replies

    0 Quotes

  8. برای برنامه Windows Disk Cleanup Utility  یا همان (cleanmgr.exe) آسیب پذیری با کد شناسایی CVE-2025-21420 و از نوع privilege escalation منتشر شده است. این آسیب پذیری باعث اجرای کدهای مخرب با دسترسی system از طریق تکنیک DLL sideloading می گردد. https://t.co/Poz3aKY03t https://t.

    @AmirHossein_sec

    21 Feb 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ⚠️ Vulnerability Alert: Windows Disk Cleanup Tool Exploit 📅 Timeline: Disclosure: 2025-02-20, Patch: 2025-02-20 📌 Attribution: 🆔cveId: CVE-2025-21420 📊baseScore: 7.8 📏cvssMetrics: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cvssSeverity: High 🟠 🛠️exploitMaturity: Actively… h

    @syedaquib77

    20 Feb 2025

    24 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. A critical vulnerability (CVE-2025-21420) in Windows Disk Cleanup Tool has been exploited to gain SYSTEM privileges. Microsoft has issued a patch in February 2025. Stay updated! 🛡️💻 #WindowsUpdate #PrivilegeEscalation #USA link: https://t.co/9lFk3Y3aoR https://t.co/NhJFLWOUNe

    @TweetThreatNews

    20 Feb 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2025-21420: Windows Disk Cleanup Tool Flaw Exploited to Gain SYSTEM Privileges, PoC Released https://t.co/WtnCkU5EVl

    @samilaiho

    20 Feb 2025

    960 Impressions

    5 Retweets

    14 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  12. CVE-2025-21420: Windows Disk Cleanup Tool Flaw Exploited to Gain SYSTEM Privileges, PoC Released https://t.co/1dOfVYHLOT

    @Dinosn

    20 Feb 2025

    2569 Impressions

    21 Retweets

    53 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  13. Windowsディスククリーンアップツールの脆弱性CVE-2025-21420に対応するPoC(攻撃の概念実証コード)が公開された。2月の定例更新で修正されていたもので、DLLサイドローディングによりSYSTEM権限の奪取が可能。 https://t.co/5B6CireRrb

    @__kokumoto

    20 Feb 2025

    1800 Impressions

    10 Retweets

    28 Likes

    10 Bookmarks

    0 Replies

    1 Quote

  14. CVE-2025-21420: Windows Disk Cleanup Tool Flaw Exploited to Gain SYSTEM Privileges, PoC Released Learn about CVE-2025-21420, a critical vulnerability in the Windows Disk Cleanup Tool that could allow SYSTEM privilege escalation https://t.co/2DkZq98yPS

    @the_yellow_fall

    20 Feb 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Warning: Proof of concept code #PoC released for CVE-2025-21420, an #ElevationOfPrivilege vulnerability in the #Windows Disk Cleanup Tool. Exploitation could grant attackers #SYSTEM privileges! #Patch #Patch #Patch https://t.co/NPvlUY0Ef4

    @CCBalert

    18 Feb 2025

    260 Impressions

    4 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  16. GitHub - Network-Sec/CVE-2025-21420-PoC: We found a way to DLL sideload with cleanmgr.exe - https://t.co/tgMU3FhoAr

    @piedpiper1616

    17 Feb 2025

    2972 Impressions

    25 Retweets

    56 Likes

    28 Bookmarks

    0 Replies

    0 Quotes

  17. #CVE-2025-21420 #Windows #cleanmgr #privesc Currently we found only the sideload part yet, but we also noted, how *probably* the privesc works. Date of post no other public PoC was to be found - this is the first. https://t.co/p1thsKynLu

    @__Br1CkeD__

    17 Feb 2025

    3 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  18. CVE-2025-21420 Windows Disk Cleanup Tool Elevation of Privilege Vulnerability https://t.co/W69vwPiMAi

    @CVEnew

    11 Feb 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations