CVE-2025-21298
Description
Windows OLE Remote Code Execution Vulnerability
In plain language
AI Act nowCVE-2025-21298 is a Windows flaw that can let an attacker run code on your PC or server over the network without any log-in or clicking—if you’re on affected Windows editions, you should act immediately by installing Microsoft’s fixes.
CVE-2025-21298 is a Windows OLE unauthenticated remote code execution issue where an attacker can trigger arbitrary code execution from the network without user interaction, making it critical to update affected Windows 10/11 and Windows Server versions to the fixed builds listed by Microsoft.
What to do now
- Check every Windows device you run (PCs, laptops, and servers) to confirm whether it is one of: windows 10, windows 11, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025, windows server 2008 r2, windows server 2012 r2.
- For each affected device, check its current Windows build number.
- Update using Microsoft’s guidance for CVE-2025-21298 and install the corresponding fixed build for your exact OS version (examples from Microsoft’s fix list below):
- windows 10: fixed in 10.0.10240.20890, 10.0.14393.7699, 10.0.17763.6775, 10.0.19044.5371, or 10.0.19045.5371
- windows 11: fixed in 10.0.22621.4751, 10.0.22631.4751, or 10.0.26100.2894
- windows server 2016: fixed in 10.0.14393.7699
- windows server 2019: fixed in 10.0.17763.6775
- windows server 2022: fixed in 10.0.20348.3091 or 10.0.25398.1369
- After updating, verify the device build number now matches one of the fixed builds for your OS family/branch.
- If you cannot patch quickly, restrict network exposure of that device immediately (especially any services that allow inbound connections from untrusted networks) until updates are applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-21298 and every CVE in our database. Create a free account — no credit card required.
Create Free Account