CVE-2025-21333
HIGH KEVWindows Hyper-V NT Kernel Integration VSP - Elevation of Privilege via Heap-based Buffer Overflow
Title source: llmExploitation Summary
CVE-2025-21333 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 14, 2025. EIP tracks 5 public exploits from researchers including Milad Karimi (Ex3ptionaL), MrAle98, nu1lptr0.
AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP. It leverages memory corruption techniques to elevate privileges, likely through kernel object manipulation and token stealing.
Description
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
Exploits (5)
This exploit targets a privilege escalation vulnerability in Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP. It leverages memory corruption techniques to elevate privileges, likely through kernel object manipulation and token stealing.
This repository contains a proof-of-concept exploit for CVE-2025-21333, targeting a Windows kernel vulnerability. The code includes structures and functions for kernel exploitation, likely involving privilege escalation via IoRing and other kernel mechanisms.
This repository contains a functional exploit for CVE-2025-21333, a Windows heap-based buffer overflow vulnerability. The exploit leverages IoRing and pipe spraying techniques to achieve arbitrary read/write primitives, with improvements over the original PoC by MrAle98.
This repository contains a functional local privilege escalation (LPE) exploit for CVE-2025-21333, a heap-based buffer overflow in Hyper-V's `vkrnlintvsp.sys` driver. The exploit leverages a pool allocation size truncation vulnerability in `VkiRootAdjustSecurityDescriptorForVmwp` to achieve arbitrary memory corruption and token manipulation for privilege escalation.
References (5)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H