CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-21311

CVSS 9.8v3.1pub. 2025-01-14upd. 2025-01-24

Windows NTLM V1 Elevation of Privilege Vulnerability

🤖 AI Analysis
How it works

The vulnerability is related to improper implementation of the NTLM authentication mechanism in version 1 (CWE-303 — error in the implementation of authentication protocol steps). An attacker can exploit the vulnerability remotely, without possessing any privileges and without user involvement, suggesting the possibility of conducting an attack directly on the NTLM network stack. The detailed technical mechanism has not been disclosed by the vendor.

Impact

Successful exploitation of the vulnerability allows an attacker to gain complete control over the system — obtaining confidential data, modifying data, and causing service unavailability (full impact on confidentiality, integrity, and availability).

Mitigation & patch

Security updates published by Microsoft as part of the January 2025 Patch Tuesday should be applied immediately, available through Microsoft Update Catalog and WSUS. Additionally, it is recommended to consider disabling or restricting the use of NTLM V1 protocol in the environment according to Microsoft guidelines (Group Policy: 'Network security: LAN Manager authentication level').

Who is affected

Microsoft Windows 11 24H2, Microsoft Windows Server 2022 23H2, Microsoft Windows Server 2025

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Windows 11 24h2

    OS
    Microsoft
    < 10.0.26100.2894
  • Microsoft Windows Server 2022 23h2

    OS
    Microsoft
    < 10.0.25398.1369
  • Microsoft Windows Server 2025

    OS
    Microsoft
    < 10.0.26100.2894
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2026-62878CRITICAL9.8same product

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-62815CRITICAL9.8same product

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

CVE-2026-62893CRITICAL9.8same product

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.