SB2025040869 - Multiple vulnerabilities in Microsoft Windows Standards-Based Storage Management Service
Published: April 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2025-21174)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Windows Standards-Based Storage Management Service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
2) Resource exhaustion (CVE-ID: CVE-2025-27485)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Windows Standards-Based Storage Management Service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
3) Resource exhaustion (CVE-ID: CVE-2025-26680)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Windows Standards-Based Storage Management Service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
4) Resource exhaustion (CVE-ID: CVE-2025-26652)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Windows Standards-Based Storage Management Service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
5) Resource exhaustion (CVE-ID: CVE-2025-27470)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Windows Standards-Based Storage Management Service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
6) Resource exhaustion (CVE-ID: CVE-2025-27486)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in Windows Standards-Based Storage Management Service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-21174
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-27485
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-26680
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-26652
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-27470
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-27486