CVE-2025-21224
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: secure@microsoft.com (Secondary)
Description
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.19044.5371 | |
| Before 10.0.19045.5371 | |
| Before 10.0.22621.4751 | |
| Before 10.0.22631.4751 | |
| Before 10.0.26100.2894 | |
| Before 10.0.20348.3091 | |
| Before 10.0.25398.1369 | |
| Before 10.0.26100.2894 |
Related CWEs
CWE-416
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-591
Sensitive Data Storage in Improperly Locked Memory
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.
References (3)
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.