Cyber Security News

Windows Driver Zero-Day Vulnerability Allow Attackers To Gain System Access Remotely

A critical zero-day vulnerability has been discovered in a Windows driver, allowing attackers to gain remote access to systems.

This vulnerability, identified as CVE-2025-21418, was disclosed on February 11, 2025, and is classified as “Important” with a CVSS score of 7.8.

The vulnerability is a heap-based buffer overflow, categorized under CWE-122.

The vulnerability exploits a weakness in the driver, enabling attackers to elevate privileges to SYSTEM level.

This means that if successfully exploited, an attacker could gain full control over the affected system.

While the Microsoft analysts identified that the CVSS vector string for this vulnerability is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C, which indicate that the attack vector is local, but the impact is severe.

Exploitability & Affected Systems

Although the vulnerability has not been publicly disclosed, exploitation has been detected. This suggests that attackers are already aware of and are utilizing this vulnerability.

The temporal score is slightly lower at 7.2, reflecting the evolving nature of the threat as more information becomes available.

This vulnerability affects a wide range of Windows systems, including Windows 10, Windows 11, and various Windows Server versions.

Microsoft has released security updates for these systems, which are crucial for mitigating the risk. For example, updates for Windows 11 Version 24H2 and Windows Server 2025 include patches with identifiers such as 5051987 and 5052105.

To protect against this vulnerability, users are advised to apply the latest security updates as soon as possible. Microsoft’s Patch Tuesday updates for February 2025 include fixes for this vulnerability.

Users should prioritize installing the latest security patches to prevent potential attacks. Staying informed about vulnerabilities and applying timely updates is crucial for maintaining system security.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago