CVE-2025-21418
Windows Ancillary Function Driver for WinSock Schwachstelle zur Erhöhung von Berechtigungen
Aktiv ausgenutzt
- Seit dem 11. Feb. 2025 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 4. März 2025 beheben (BOD 22-01)
- Angegriffen 1 Tag bevor die Schwachstelle öffentlich wurde
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 20. Jan. 2026 11. Feb. 2025 11. Feb. 2025 11. Feb. 2025 11. Feb. 2025
CVSS-Score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-122
Herstellermicrosoft
Betroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| microsoft | windows 10 1607 | < 10.0.10240.20915 |
| microsoft | windows 10 1809 | < 10.0.17763.6893 |
| microsoft | windows 10 21h2 | < 10.0.19044.5487 |
| microsoft | windows 10 22h2 | < 10.0.19045.5487 |
| microsoft | windows 11 22h2 | < 10.0.22621.4890 |
| microsoft | windows 11 23h2 | < 10.0.22631.4890 |
| microsoft | windows 11 24h2 | < 10.0.26100.3107 |
| microsoft | windows server 2008 | - |
| microsoft | windows server 2012 | - |
| microsoft | windows server 2016 | < 10.0.14393.7785 |
| microsoft | windows server 2019 | < 10.0.17763.6893 |
| microsoft | windows server 2022 | < 10.0.20348.3148 |
| microsoft | windows server 2022 23h2 | < 10.0.25398.1425 |
| microsoft | windows server 2025 | < 10.0.26100.3107 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.
