CVE detail
CVE-2025-21194
Microsoft Surface Security Feature Bypass Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- Microsoft Patch Tuesday security updates for February 2025 ficed 2 actively exploited bugsSecurity Affairs
Microsoft Patch Tuesday security updates for February 2025 addressed four zero-day flaws, two of which are actively exploited in the wild. Microsoft Patch Tuesday security updates for February 2025 addressed 57 vulnerabilities in Windows and Windows Components, Office and Office Components, Azure, Visual Studio, and Remote Desktop Services. Two of these vulnerabilities are listed as […]
newssecurityaffairs.comFeb 12, 2025, 7:27 AM February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation. CVE-2025-21418 and CVE-2025-21391 CVE-2025-21418 is a vulnerability in the Windows Ancillary Function Driver (AFD.sys), which interfaces with the Windows Sockets API to enable Windows applications to connect to the internet. It can be exploited by attackers to elevate privileges on the target host. “An authenticated user would need to run … More →
newswww.helpnetsecurity.comFeb 11, 2025, 8:15 PMThe Microsoft Patch Tuesday machine hummed loudly this month with urgent fixes for a pair of already-exploited Windows zero-days.
newswww.securityweek.comFeb 11, 2025, 7:59 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21194msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comFeb 11, 2025, 6:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48581CVSS 7.8 · High
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
- CVE-2026-72867CVSS 9.9 · Critical
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts bra…
- CVE-2026-72728CVSS 6.3 · Medium
Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malici…
- CVE-2026-42537CVSS N/A · Unrated
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-40920CVSS N/A · Unrated
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-21083CVSS 6.8 · Medium
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.