LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-21334: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 14, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 4, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-21334 to its Known Exploited Vulnerabilities catalog on Jan 14, 2025, with a federal patch deadline of Feb 4, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

CVE-2025-21334 is a use-after-free flaw in the Microsoft Windows Hyper-V NT Kernel Integration VSP component. A local attacker who already has some access on an affected system can abuse it to elevate privileges to SYSTEM.

This matters for any organization running Hyper-V because SYSTEM-level control of a hypervisor host can expose guest virtual machines, management tooling, and connected infrastructure. Confirm exact impact and affected builds against the Microsoft advisory.

How it works

The vulnerability is classified as CWE-416 (use-after-free). In this class of flaw, memory that has already been freed is later accessed again. An attacker who can influence the timing or content of that access may corrupt kernel structures or redirect execution.

According to the CISA summary, the issue resides in the Hyper-V NT Kernel Integration VSP. A local attacker can trigger the condition to obtain SYSTEM privileges. Public detail on the precise trigger path is limited; treat any exploit description outside the vendor advisory as unverified. Because the attack requires local access, it is typically chained after an initial foothold such as a compromised low-privilege account or another local vulnerability.

Am I affected? How to find it in your systems

The component is part of Microsoft Windows systems that have Hyper-V installed or enabled. It commonly appears on Windows Server hosts used as hypervisors, Windows 10/11 machines with the Hyper-V feature turned on, and related virtualization management roles.

If Hyper-V is not installed or the feature is disabled, exposure is typically lower, but still verify residual components against the vendor guidance.

How to remediate

Apply the security update published by Microsoft for CVE-2025-21334 as the primary remediation. Follow the exact package, servicing stack, and reboot guidance in the official advisory; confirm applicability for each Windows edition and build in your environment.

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Follow that directive.

If you can't patch immediately

Until the vendor update can be deployed, reduce the attack surface with compensating controls:

These steps do not eliminate the vulnerability; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities can be used to establish persistence, dump credentials, or move laterally, potentially leading to broader data exposure. Ransomware use of this specific CVE is not documented. If you suspect compromise of a Hyper-V host, isolate the system, preserve forensic evidence, rotate credentials that may have been present in memory, and review guest VM integrity. You can also run a free exposure scan of your email addresses against known breach data sets to check whether related accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-416
Added to CISA KEVJan 14, 2025
Federal patch deadlineFeb 4, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities