

DanaBot Trojan – Active IOCs
January 30, 2025
Multiple WordPress Plugins Vulnerabilities
January 30, 2025
DanaBot Trojan – Active IOCs
January 30, 2025
Multiple WordPress Plugins Vulnerabilities
January 30, 2025Severity
High
Analysis Summary
CVE-2025-21293 CVSS:8.8
Microsoft Windows could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Active Directory Domain Services component.
CVE-2025-21282 CVSS:8.8
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in Telephony Service component.
CVE-2025-21241 CVSS:8.8
Microsoft Windows Telephony Service could allow a remote attacker to execute arbitrary code on the system when visiting a specially crafted Website.
CVE-2025-21235 CVSS:7.8
Microsoft Windows PrintWorkflowUserSvc could allow a local authenticated attacker to elevate privileges from a Low Integrity Level in a contained ("sandboxed") execution environment to a Medium Integrity Level.
CVE-2025-21234 CVSS:7.8
Microsoft Windows PrintWorkflowUserSvc could allow a local authenticated attacker to elevate privileges from a Low Integrity Level in a contained ("sandboxed") execution environment to a Medium Integrity Level.
Impact
- Privilege Escalation
- Code Execution
Indicators of Compromise
CVE
CVE-2025-21293
CVE-2025-21282
CVE-2025-21241
CVE-2025-21235
CVE-2025-21234
Affected Vendors
- Microsoft
Affected Products
- Microsoft Windows 10 Version 1809 - 10.0.17763.0
- Microsoft Windows Server 2019 - 10.0.17763.0
- Microsoft Windows Server 2019 (Server Core installation) - 10.0.17763.0
- Microsoft Windows Server 2022 - 10.0.20348.0
- Microsoft Windows 11 Version 23H2 - 10.0.22631.0
- Microsoft Windows 10 Version 21H2 - 10.0.19043.0
- Microsoft Windows Server 2025 - 10.0.26100.0
- Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation) - 6.1.7601.0
- Microsoft Windows Server 23H2 Edition (Server Core installation) - 10.0.25398.0
- Microsoft Windows Server 2008 R2 Service Pack 1 - 6.1.7601.0
Remediation
Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.