BDU:2025-00287
Scores
EPSS
Percentile: 0.0%
CVSS
CVSS Score: 7.8/10
All CVSS Scores
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector Breakdown
CVSS (Common Vulnerability Scoring System) vector provides detailed metrics about vulnerability characteristics
CVSS
Attack Vector
Local (L)
Describes how the vulnerability is exploited
Attack Complexity
Low (L)
Describes the conditions beyond the attacker's control
Privileges Required
Low (L)
Describes the level of privileges an attacker must possess
User Interaction
None (N)
Captures the requirement for a human user participation
Scope
Unchanged (U)
Determines if a successful attack impacts components beyond the vulnerable component
Confidentiality Impact
High (H)
Measures the impact to the confidentiality of information
Integrity Impact
High (H)
Measures the impact to integrity of a successfully exploited vulnerability
Availability Impact
High (H)
Measures the impact to the availability of the impacted component
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
Vector Breakdown
CVSS (Common Vulnerability Scoring System) vector provides detailed metrics about vulnerability characteristics
CVSS
Attack Vector
Local (L)
Describes how the vulnerability is exploited
Attack Complexity
Low (L)
Describes the conditions beyond the attacker's control
Authentication
Single
Describes the level of privileges an attacker must possess
Confidentiality Impact
Complete
Measures the impact to the confidentiality of information
Integrity Impact
Complete
Measures the impact to integrity of a successfully exploited vulnerability
Availability Impact
Complete
Measures the impact to the availability of the impacted component
Description
Уязвимость функции VSP Elevation ядра системы аппаратной виртуализации Windows Hyper-V операционных систем Windows связана с переполнением буфера в динамической памяти. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии до уровня SYSTEM
Scaner-VS 7 — a modern vulnerability management solution
Sources
Related Vulnerabilities
Exploits
Exploit ID: CVE-2025-21333
Source: github-poc
Recommendations
Source: bdu
Установка обновлений из доверенных источников. В связи со сложившейся обстановкой и введенными санкциями против Российской Федерации рекомендуется устанавливать обновления программного обеспечения только после оценки всех сопутствующих рисков.
Компенсирующие меры:
- использование средств контроля целостности для отслеживания конфигураций, привилегированных операций и некорректного поведения виртуальных машин
- использование средств обнаружения и предотвращения вторжений (IDS/IPS) для отслеживания попыток эксплуатации уязвимости;
- минимизация пользовательских привилегий;
- отключение/удаление неиспользуемых учётных записей пользователей.
Использование рекомендаций производителя:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21333
Vulnerable Software (109)
Type: Configuration
Vendor: microsoft corp
Product: windows_10 21h2
Operating System: * *
{ "version_exact": "*"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_10 22h2
Operating System: * *
{ "version_exact": "*"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_11 22h2
Operating System: * *
{ "version_exact": "*"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_11 23h2
Operating System: * *
{ "version_exact": "*"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_11 24h2
Operating System: * *
{ "version_exact": "*"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_server_2022,
Operating System: * *
{ "version_exact": "23h2 edition (server core installation)"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_server_2025
Operating System: * *
{ "version_exact": "*"}
Source: bdu
Type: Configuration
Vendor: microsoft corp
Product: windows_server_2025
Operating System: * *
{ "version_exact": "(server core installation)"}
Source: bdu
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 10.0.26200.8246
Operating System: Windows 26200 build 8246
Identifier: KB5083769
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.8117
Operating System: Windows 26100 build 8117
Identifier: KB5086672
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.8116
Operating System: Windows 26100 build 8116
Identifier: KB5079391
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.8039
Operating System: Windows 26100 build 8039
Identifier: KB5085516
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 10.0.26200.8037
Operating System: Windows 26200 build 8037
Identifier: KB5079473
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.7922
Operating System: Windows 26100 build 7922
Identifier: KB5077241
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 10.0.26200.7840
Operating System: Windows 26200 build 7840
Identifier: KB5077181
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.7705
Operating System: Windows 26100 build 7705
Identifier: KB5074105
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.7628
Operating System: Windows 26100 build 7628
Identifier: KB5078127
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 26100.7627
Operating System: Windows 26100 build 7627
Identifier: KB5077744
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 10.0.26200.7623
Operating System: Windows 26200 build 7623
Identifier: KB5074109
Source: msrc
Type: Windows KB
Vendor: Microsoft
Product: Windows
Version: 10.0.26200.7462
Operating System: Windows 26200 build 7462
Identifier: KB5072033
Source: msrc