LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-21335: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 14, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 4, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-21335 to its Known Exploited Vulnerabilities catalog on Jan 14, 2025, with a federal patch deadline of Feb 4, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

CVE-2025-21335 is a use-after-free vulnerability in the Microsoft Windows Hyper-V NT Kernel Integration VSP component. A local attacker can exploit it to gain SYSTEM privileges on the affected host.

This matters for IT and security teams because Hyper-V underpins virtualization on many Windows systems. Successful privilege escalation to SYSTEM can give an attacker full control of the host, enabling lateral movement, persistence, or compromise of guest virtual machines. Confirm all details against the vendor advisory before acting.

How it works

The flaw is classified as CWE-416, a use-after-free condition. In this class of weakness, a program frees a block of memory but later continues to reference or write to that same location. An attacker who can influence the timing and content of those references may corrupt kernel structures or redirect execution flow.

According to the available summary, the issue resides in the Hyper-V NT Kernel Integration VSP. A local attacker with the ability to interact with this component can trigger the use-after-free and elevate privileges to SYSTEM. Exact exploit mechanics, required access rights short of local presence, and any race conditions are not detailed in the public record; teams must treat the vulnerability as a local privilege-escalation risk and verify specifics in the Microsoft advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Hyper-V NT Kernel Integration VSP. Hyper-V is commonly enabled on Windows Server hosts used for virtualization, on Windows client machines running local virtual machines, and in some nested or cloud-hosted Windows environments.

How to remediate

The primary remediation is to apply the security update provided by Microsoft for this vulnerability. Follow the vendor’s installation instructions exactly, including any required reboots and any prerequisites listed in the advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls.

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to full host compromise and subsequent data breaches. Although ransomware use of this specific CVE is not documented, any successful elevation to SYSTEM warrants investigation for unauthorized access, credential theft, or data exfiltration. Review host and network logs for indicators of post-exploitation activity. As a further check, individuals can run a free exposure scan of their email addresses against known breach data sets to determine whether personal credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-416
Added to CISA KEVJan 14, 2025
Federal patch deadlineFeb 4, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities