Rewterz
DarkCrystal RAT aka DCRat – Active IOCs
January 20, 2025
Rewterz
Gafgyt aka Bashlite Malware – Active IOCs
January 20, 2025

Multiple Microsoft Windows Vulnerabilities

Severity

High

Analysis Summary

CVE-2025-21271 CVSS:7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability.

CVE-2025-21266 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

CVE-2025-21252 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

CVE-2025-21248 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

CVE-2025-21244 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

CVE-2025-21243 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

CVE-2025-21413 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

CVE-2025-21411 CVSS:8.8

Windows Telephony Service Remote Code Execution Vulnerability.

Impact

  • Privilege Escalation
  • Code Execution

Indicators of Compromise

CVE

  • CVE-2025-21271

  • CVE-2025-21266

  • CVE-2025-21252

  • CVE-2025-21248

  • CVE-2025-21244

  • CVE-2025-21243

  • CVE-2025-21413

  • CVE-2025-21411

Affected Vendors

Microsoft

Affected Products

  • Microsoft Windows Server 2022
  • Microsoft Windows 10 Version 1809 - 10.0.17763.0
  • Microsoft Windows Server 2019 - 10.0.17763.0
  • Microsoft Windows Server 2019 (Server Core installation) - 10.0.17763.0
  • Microsoft Windows Server 2022 - 10.0.20348.0
  • Microsoft Windows Server 2012 (Server Core installation) - 6.2.9200.0
  • Microsoft Windows Server 2012 R2 - 6.3.9600.0
  • Microsoft Windows Server 2012 R2 (Server Core installation) - 6.3.9600.0
  • Microsoft Windows Server 2012 - 6.2.9200.0
  • Microsoft Windows 11 Version 24H2 - 10.0.26100.0
  • Microsoft Windows Server 2008 Service Pack 2 (Server Core installation) - 6.0.6003.0
  • Microsoft Windows Server 2008 Service Pack 2 - 6.0.6003.0
  • Microsoft Windows Server 2016 - 10.0.14393.0
  • Microsoft Windows Server 2016 (Server Core installation) - 10.0.14393.0

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2025-21271

CVE-2025-21266

CVE-2025-21252

CVE-2025-21248

CVE-2025-21244

CVE-2025-21243

CVE-2025-21413

CVE-2025-21411