CVE-2025-21389Uncontrolled Resource Consumption in Microsoft Windows 10 Version 1507

Severity
7.5HIGHNVD
EPSS
2.4%
top 14.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14

Description

Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages26 packages

CVEListV5microsoft/windows_server_2008_service_pack_26.0.6003.06.0.6003.23070
CVEListV5microsoft/windows_server_2008_r2_service_pack_16.1.7601.06.1.7601.27520
NVDmicrosoft/windows< 10.0.14393.7699+5
NVDmicrosoft/windows_10_1507< 10.0.10240.20890
NVDmicrosoft/windows_10_1607< 10.0.14393.7699

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8fj2-r7qc-chj6: Windows upnphost2025-01-14
CVEList
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability2025-01-14

📋Vendor Advisories

1
Microsoft
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability2025-01-14

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws2025-01-14
CVE-2025-21389 — Uncontrolled Resource Consumption | cvebase