CVE-2025-21333Exploit(microsoft / windows_10_21h2)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_21h2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-02-04. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-122

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_21h2
  • windows_10_22h2
  • windows_11_22h2
  • windows_11_23h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Peaked 3d ago at 1 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-05-06: 1Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-05-06: 1Active Exploitation · 2026-07-10: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-07-10: 102-0405-0505-0607-10
Signal classification3 categories
Exploit
250.0%
Patch
125.0%
Active Exploitation
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-05-051
Exploit1
2026-05-061
Exploit1
2026-07-101
Active Exploitation1
Full discourse4 posts
  • nu1lptr@_4bhishek
    Exploit

    CVE-2025-21333: poc https://github.com/nu1lptr0/CVE-2025-21333 (Integer truncation in vkrnlintvps.sys) Rewrote this exploit which is less sketchy as it doesn't open windows sandbox and little bit more stable. https://t.co/utkIobKFet

    Post summary

    The post shares a rewritten exploit (PoC code) for CVE-2025-21333 targeting an integer truncation issue in vkrnlintvps.sys, but provides no evidence of active attacks or patches.

    13201358410.4K
    458 followersView on X
  • DEFION | Ciberseguridad@defionsecurity
    Active Exploitation

    CVEs con explotación activa confirmada en junio: 🔴 CVE-2025-0282 · Ivanti VPN · RCE pre-auth (9.0) 🔴 CVE-2024-55591 · FortiOS · Auth bypass (9.8) 🟠 CVE-2025-21333 · Hyper-V · LPE (7.8) Tiempo medio de explotación desde publicación: <5 días. Nuestro equipo de ITE los tiene en el radar antes de que llegue el aviso.

    Post summary

    The message reports confirmed active exploitation of three CVEs in June, providing basic technical details but no PoC, patch, or tool information.

    00010152
    868 followersView on X
  • DarkRelay Security Labs@darkrelaylabs
    Exploit

    CVE-2025-21333 exploit evolution: ❌ IoRing spray (SubmitIoRing batch) → crash ✅ Pipe attrs → arbitrary read ✅ Refined IoRing spray → arbitrary write MDAG API for stable GUID (no sandbox) Thread priority matters. https://github.com/nu1lptr0/CVE-2025-21333 #Cybersecurity #Windows #Infosec

    Post summary

    The text describes the evolution of a functional exploit for CVE-2025-21333, detailing specific techniques and providing a link to code that implements the attack.

    000101.1K
    146 followersView on X
  • RagingCISO@CisoRaging77913
    Patch

    CVE-2025-21333/21334 + CVE-2026-20805: Hyper-V zero-days → SYSTEM access. DWM leaks memory to fuel exploit chains. 157 CVEs, 8 zero-days, one Patch Tuesday. CISA deadline expired today. Your critical servers run Hyper-V. Assume compromised if unpatched. Sweet dreams.

    Post summary

    The post highlights unpatched Hyper‑V servers at risk of zero‑day exploitation with SYSTEM access, noting a Patch Tuesday patch is available and urging immediate remediation.

    00000140
    4 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2022_23h2--x64
OSmicrosoftwindows_server_2025--x64

Explore more