Database/Kernel, userspace & hypervisor

Microsoft Hyper-V: Heap-based buffer overflow in the NT Kernel Integration VSP
CVSS 7.8CVE-2025-21333Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Heap-based buffer overflow in the NT Kernel Integration VSP - elevation of privilege, exploited in the wild [KEV]
Who can reach it
Local user on the Hyper-V host (or a container using the VSP path)
What to do
Windows update + host reboot with VM live-migration
References
Related entries
- Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildCVE-2025-21334 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: Use-after-free in the NT Kernel Integration VSP - elevation of privilege, exploited in the wildCVE-2025-21335 · Microsoft Hyper-VHigh
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Microsoft Hyper-V: Hyper-V elevation of privilege, exploited in the wildCVE-2024-38080 · Microsoft Hyper-VHigh
- Linux kernel (drivers/vfio/platform): Vfio-platform never bounds-checked the count and offset a caller passes toCVE-2025-21687 · Linux kernel (drivers/vfio/platform)High
- Linux kernel mlx5_ib on-demand paging (ODP): Implicit on-demand-paging memory region destroy work can be queued twiceCVE-2025-21714 · Linux kernel mlx5_ib on-demand paging (ODP)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.