Vulnerability record · CVE-2025-21391 · published 11 February 2025
CVE-2025-21391: Microsoft Windows Storage Elevation of Privilege via Link Following
Microsoft · Windows 10 1507
CVE-2025-21391 is a link-following flaw in the Windows Storage component that lets a local user escalate privileges. It affects a broad set of Windows 10, Windows 11, and Windows Server releases, and Microsoft rates it high severity. Because it is listed in CISA KEV, it is being exploited in the wild.
Description
Windows Storage Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Automated analysis
high priorityIt is confirmed exploited in CISA KEV and affects a wide range of Windows versions, though it requires local access and has no confidentiality impact.
What it is
CVE-2025-21391 is a link-following flaw in the Windows Storage component that lets a local user escalate privileges. It affects a broad set of Windows 10, Windows 11, and Windows Server releases, and Microsoft rates it high severity. Because it is listed in CISA KEV, it is being exploited in the wild.
Impact
An attacker with local access gains elevated privileges on the host, with high impact to integrity and availability. The CVSS vector shows no confidentiality impact, so the primary gain is the ability to modify or disrupt system state at a higher privilege level.
Attack surface
The vector is local (AV:L) with low attack complexity, low privileges required, and no user interaction. The attacker must already have code execution or an interactive session on the target Windows system.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-11 with a remediation due date of 2025-03-04, confirming active exploitation. EPSS gives a 30-day probability of about 2.3 percent (82nd percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2025-21391 across all affected Windows 10, Windows 11, and Windows Server builds.
- Prioritize patching systems where untrusted users already have local access, such as multi-user endpoints, terminal servers, and jump hosts.
- Follow the CISA KEV required action: apply vendor mitigations or discontinue use of the product where mitigations are unavailable.
- Restrict local logon and interactive session rights to reduce the population of users who can reach the vulnerable component.
- Monitor for and remove unnecessary reparse points or symlinks in storage paths that could be abused for link following.
Detection
- Alert on processes creating reparse points or symbolic links in storage-related paths, especially from non-administrative contexts.
- Monitor Windows event logs for privilege escalation indicators, such as unexpected token elevation or service creation shortly after file or link operations.
- Hunt for unusual writes or deletions in storage-managed directories by low-privileged accounts.
- Track hosts that remain unpatched against the February 2025 Microsoft updates and correlate with local logon activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-21391 to the Known Exploited Vulnerabilities catalog on 11 February 2025 as "Microsoft Windows Storage Link Following Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 March 2025.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21391 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21391 | US Government Resource |
Track CVE-2025-21391 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-21391), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.