CVE Vulnerabilities

CVE-2025-21311

Incorrect Implementation of Authentication Algorithm

Published: Jan 14, 2025 | Modified: Jan 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Windows NTLM V1 Elevation of Privilege Vulnerability

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

NameVendorStart VersionEnd Version
Windows_11_24h2Microsoft*10.0.26100.2894 (excluding)
Windows_server_2022_23h2Microsoft*10.0.25398.1369 (excluding)
Windows_server_2025Microsoft*10.0.26100.2894 (excluding)
SquidUbuntudevel*
SquidUbuntuesm-infra/focal*
SquidUbuntujammy*
SquidUbuntunoble*
SquidUbuntuplucky*
SquidUbuntuupstream*
Squid3Ubuntuesm-infra/bionic*
Squid3Ubuntuesm-infra/xenial*

References