CISA Known Exploited Vulnerability (KEV)
Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
January 14, 2025
February 4, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21333
- https://www.vicarius.io/vsociety/posts/cve-2025-21333-elevated-privilege-exposure-in-windows-hyper-v-by-microsoft-detection-script
- https://www.vicarius.io/vsociety/posts/cve-2025-21333-elevated-privilege-exposure-in-windows-hyper-v-by-microsoft-mitigation-script
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-122 |
Heap-based Buffer Overflow |