---
title: Patch Tuesday - February 2025
description: CVE-2025-21391 & CVE-2025-21418 are elevation of privilege vulnerabilities in Windows Storage and the Windows Ancillary Function Driver (AFD) for WinSock.
---

[Cybersecurity Blog | RedLegg ](https://www.redlegg.com/blog)

# [Patch Tuesday - February 2025](https://www.redlegg.com/blog/critical-vulnerability-patch-tuesday-february-2025)

 Written by [RedLegg Blog](https://www.redlegg.com/blog/author/redlegg-blog) | 2/12/25 3:30 PM

**Important note: These are not the only vulnerabilities that were recently released; however, these are the vulnerabilities RedLegg has identified as critical and require immediate attention.*

## VULNERABILITIES

### Windows Storage Elevation of Privilege Vulnerability

CVSS Score: 7.1 (High)   
Identifier: CVE-2025-21391   
Exploit or POC: Yes, active exploitation has been observed in the wild.   
Update: CVE-2025-21391 – [Microsoft Security Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21391?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--VZU4B1R5xG-aSnyy_jvzRTUaahidDm3MeJxvsFtap-oIwZF1uF04CNDtTij9Zny64FGyg)

Description: CVE-2025-21391 is an elevation of privilege vulnerability in Windows Storage. This flaw allows a local, authenticated attacker to delete targeted files on a system, potentially leading to service disruption. While it does not permit the disclosure of confidential information, the unauthorized deletion of critical files can render services unavailable.

Mitigation Recommendation: Patching is currently the only method of mitigation. Microsoft has released security updates to address this vulnerability. Administrators are advised to apply the latest patches as specified in the [Microsoft Security Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21391?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--VZU4B1R5xG-aSnyy_jvzRTUaahidDm3MeJxvsFtap-oIwZF1uF04CNDtTij9Zny64FGyg). Immediate patching is recommended to prevent potential exploitation.

Note: *Given the active exploitation of this vulnerability, it is imperative to apply the recommended patches promptly to secure your systems.*

### Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS Score: 7.8 (High)   
Identifier: CVE-2025-21418   
Exploit or POC: Yes, active exploitation has been observed in the wild.   
Update: CVE-2025-21418 – [Microsoft Security Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21418?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--VZU4B1R5xG-aSnyy_jvzRTUaahidDm3MeJxvsFtap-oIwZF1uF04CNDtTij9Zny64FGyg)

Description: CVE-2025-21418 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock. This flaw allows a local, authenticated attacker to execute code with SYSTEM privileges by running a specially crafted program. Successful exploitation could lead to a complete system compromise. Microsoft has reported active exploitation of this vulnerability in the wild.

Mitigation Recommendation: Patching is currently the only method of mitigation. Microsoft has released security updates to address this vulnerability. Administrators are advised to apply the latest patches as specified in the [Microsoft Security Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21418?utm_campaign=Threat%20Intel&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--VZU4B1R5xG-aSnyy_jvzRTUaahidDm3MeJxvsFtap-oIwZF1uF04CNDtTij9Zny64FGyg). Immediate patching is recommended to prevent potential exploitation.

Note: *Given the active exploitation of this vulnerability, it is imperative to apply the recommended patches promptly to secure your systems.*

[View full post](https://www.redlegg.com/blog/critical-vulnerability-patch-tuesday-february-2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "RedLegg Blog"
  },
  "dateModified" : "2025-02-12T15:30:32.505Z",
  "datePublished" : "2025-02-12T15:30:32Z",
  "headline" : "Patch Tuesday - February 2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 630,
    "url" : "https://www.redlegg.com/hubfs/Blog%20Featured%20Image%20-Critical%20Bulletin%20v2.png",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://www.redlegg.com/blog/critical-vulnerability-patch-tuesday-february-2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/4675768/logo-red-01.png",
      "width" : 419.66666
    },
    "name" : "RedLegg Cybersecurity Blog"
  }
}
```