CVE-2025-21368
published 2025-02-11CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.30%
81.5th percentile
Microsoft Digest Authentication Remote Code Execution Vulnerability
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20915 | 10.0.10240.20915 |
| microsoft | windows_10_1607 | < 10.0.14393.7785 | 10.0.14393.7785 |
| microsoft | windows_10_1809 | < 10.0.17763.6893 | 10.0.17763.6893 |
| microsoft | windows_10_21h2 | < 10.0.19044.5487 | 10.0.19044.5487 |
| microsoft | windows_10_22h2 | < 10.0.19045.5487 | 10.0.19045.5487 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20915 | 10.0.10240.20915 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7785 | 10.0.14393.7785 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6893 | 10.0.17763.6893 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5487 | 10.0.19044.5487 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5487 | 10.0.19045.5487 |
| microsoft | windows_11_22h2 | < 10.0.22621.4890 | 10.0.22621.4890 |
| microsoft | windows_11_23h2 | < 10.0.22631.4890 | 10.0.22631.4890 |
| microsoft | windows_11_24h2 | < 10.0.26100.3194 | 10.0.26100.3194 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.4890 | 10.0.22621.4890 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.4890 | 10.0.22631.4890 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.4890 | 10.0.22631.4890 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.3194 | 10.0.26100.3194 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27566 | 6.1.7601.27566 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23117 | 6.0.6003.23117 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25317 | 6.2.9200.25317 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22417 | 6.3.9600.22417 |
| microsoft | windows_server_2016 | < 10.0.14393.7785 | 10.0.14393.7785 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7785 | 10.0.14393.7785 |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is a malicious logon request sent to a target domain controller — monitor domain controller authentication logs for anomalous or malformed Digest Authentication logon requests from authenticated (low-privilege) users. ↗
- →Any authenticated (low-privilege) user can trigger this RCE; scope detection to all authenticated principals, not just privileged accounts. ↗
- →Focus monitoring on the Microsoft Digest Authentication component (digests/SSPI stack) on domain controllers for unexpected code execution or process spawning. ↗
- ·Exploit has not been publicly disclosed or observed in the wild at time of advisory publication; exploitation is rated 'Less Likely' by Microsoft. ↗
- ·Customer action (patching) is required; multiple KB updates are listed across affected Windows releases. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Digest Authentication Remote Code Execution Vulnerability
vendor_msrc·2025-02-11·CVSS 8.8
CVE-2025-21368 [HIGH] CWE-122 Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To successfully exploit this remote code execution vulnerability, an attacker could send a malicious logon request to the target domain controller.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
Microsoft Digest Authentication: Microsoft Digest Authentication
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.
GHSA
GHSA-4hpj-87mp-j2fq: Microsoft Digest Authentication Remote Code Execution Vulnerability
ghsa_unreviewed·2025-02-11
CVE-2025-21368 [HIGH] CWE-122 GHSA-4hpj-87mp-j2fq: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-02-11·CVSS 8.7
CVE-2025-21376 [HIGH] Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for February of 2025 which includes 63 vulnerabilities affecting a range of products, including 4 that Microsoft marked as “critical” and one marked as "moderate."
There are two notable "critical" vulnerabilities. The first is CVE-2025-21376, which is a remote code execution (RCE) vulnerability affecting the Windows Lightweight Directory Access Protocol (LDAP). This vulnerability is a remote unauthenticated Out-of-bounds Write (OOBW) caused by a race condition in LDAP and could potentially result in arbitrary code execution in the Local Security Authority Subsystem Service (lsass.exe). This is a process in the Microsoft Windows operating systems that is responsible for enforcing the security policy on the system. Successful exploitation o
Talos
Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-02-11·CVSS 8.7
CVE-2025-21376 [HIGH] Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for February of 2025 which includes 63 vulnerabilities affecting a range of products, including 4 that Microsoft marked as “critical” and one marked as "moderate."
There are two notable "critical" vulnerabilities. The first is CVE-2025-21376 , which is a remote code execution (RCE) vulnerability affecting the Windows Lightweight Directory Access Protocol (LDAP). This vulnerability is a remote unauthenticated Out-of-bounds Write (OOBW) caused by a race condition in LDAP and could potentially result in arbitrary code execution in the Local Security Authority Subsystem Service (lsass.exe). This is a process in the Microsoft Windows operating systems tha
Bleepingcomputer
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
blogs_bleepingcomputer·2025-02-11·CVSS 7.1
[HIGH] Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
## Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
## Lawrence Abrams
19 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
22 Remote Code Execution Vulnerabilities
1 Information Disclosure Vulnerabilities
9 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The above numbers do not include a critical Microsoft Dynamics 365 Sales elevation of privileges flaw and 10 Microsoft Edge vulnerabilities fixed on February 6.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5051987 & KB5051989 cumulative updates and the Windows 10 KB5051974 update .
## Two actively exploited zero-day disclosed
This month's Patch Tuesday fixes two actively exploited and two public
2025-02-11
Published