← back
CVE-2025-21333highunder attackCWE-122

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 10.0%
from disclosure to weapon44 days
Published on NVDJan 14
1st PoC+44d
CISA KEVJan 14
exploitation probability
10.0%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
13 public exploit(s)
Action required by CISAfederal deadline: 2025-02-04

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

A security flaw in Windows Hyper-V's kernel integration component allows an attacker with local access to gain higher system privileges than they should have. This is dangerous because it can lead to complete control of the computer.

Technical detail

This elevation of privilege vulnerability exists in the Hyper-V NT Kernel Integration VSP (virtualization service provider) component. An attacker with local system access can exploit a privilege escalation flaw to obtain elevated kernel-level permissions, potentially leading to full system compromise and unauthorized access to sensitive resources.

Summary generated and translated by AI from the official description.
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.