Sploitus

CVE-2025-21204

3 known exploits for CVE-2025-21204

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Affected products
Windows, Windows Update Stack
Microsoft Windows 10 1507
< 10.0.10240.20978
Microsoft Windows 10 1607
< 10.0.14393.7969
Microsoft Windows 10 1809
< 10.0.17763.7136
Microsoft Windows 10 21h2
< 10.0.19044.5737
Microsoft Windows 10 22h2
< 10.0.19045.5737
Microsoft Windows 11 22h2
< 10.0.22621.5189
CVSS 3.1
7.8 HIGH
EPSS
6.9% (94th percentile)
Weakness
CWE-59
NVD status
Analyzed
Published
2025-04-08
CVE-2025-21204 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2025-21204

Proof-of-concept code and exploit modules indexed by Sploitus