CVE-2025-21343HighCVSS 7.5

Windows Web Threat Defense User Service Information Disclosure Vulnerability

Published
January 14, 2025
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.

How could an attacker exploit this vulnerability? An attacker who successfully exploited this vulnerability could capture screenshots of another user’s session, crossing the user-session boundary.

🎯 Affected products6

  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems

✅ Remediation

KB5050021 (Security Update) — fixed build 10.0.22621.4751 KB5050021 (Security Update) — fixed build 10.0.22631.4751 KB5050009 (Security Update) — fixed build 10.0.26100.2894

🔗 References (5)