7.4
CVE-2025-21182
- EPSS 0.14%
- Veröffentlicht 11.02.2025 18:15:29
- Zuletzt bearbeitet 25.02.2025 16:59:25
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 11 24h2 Version < 10.0.26100.3107
Microsoft ≫ Windows Server 2025 HwPlatformx64 Version < 10.0.26100.3107
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.339 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 7.4 | 1.4 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-415 Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.