Heap-based buffer overflow in Microsoft Windows and Windows Server - CVE-2025-21333
Published: January 14, 2025 / Updated: May 22, 2026
Vulnerability identifier: #VU102617
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21333
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in Windows Hyper-V NT Kernel Integration VSP component. A local user can trigger a heap-based buffer overflow and execute arbitrary code with SYSTEM privileges.
Note, the vulnerability is being actively exploited in the wild.Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2025-21333
Install updates from vendor's website.
Microsoft Windows - addressed in versions 10 21H2 10.0.19044.5371, 10 22H2 10.0.19045.5371, 11 22H2 10.0.22621.4751, 11 23H2 10.0.22631.4751, 11 24H2 10.0.26100.3107
Windows Server - addressed in versions 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2025 10.0.26100.2894
Windows Server - addressed in versions 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1369, 2025 10.0.26100.2894
Links to Public Exploits and PoC-codes
- Exploit #12723 - CVE-2025-21333 (May 22, 2026)
- Exploit #11948 - CVE-2025-21333-POC (?️ Exploit CVE-2025-21333 in vkrnlintvsp.sys with this proof of concept, aimed at demonstrating potential threats on Windows 11 systems.) (September 12, 2025)
- Exploit #11231 - CVE-2025-21333-POC (POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY) (March 18, 2025)
- Exploit #11230 - CVE-2025-21333-POC (March 18, 2025)
- Exploit #11215 - CVE-2025-21333-POC (March 14, 2025)
- Exploit #11185 - CVE-2025-21333-POC (February 28, 2025)