SB2025011461 - Multiple vulnerabilities in Microsoft Windows Kernel Memory
Published: January 14, 2025 Updated: March 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21320)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
2) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21317)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
3) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21321)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
4) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21319)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
5) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21323)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
6) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21316)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
7) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2025-21318)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in Windows Kernel Memory. A local user can read the log files and gain access to sensitive data.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21320
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21317
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21321
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21319
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21323
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21316
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21318