logo

How to Address CVE-2025-21307 Without a Patch Before the Weekend

ID: 9ba6ed49-6a5a-5691-8bb0-7b85072166cf

STIX ID: report--9ba6ed49-6a5a-5691-8bb0-7b85072166cf

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2025-01-17

Date Updated: 2026-04-28

Author: Eran Livne

...
...

Microsoft’s January 2025 Patch Tuesday addresses CVE-2025-21307, a critical (CVSS 9.8) remote code execution vulnerability in the Windows Reliable Multicast Transport Driver (RMCAST) that can be exploited by unauthenticated remote attackers sending crafted packets to a PGM listening socket; the report explains the risk, deployment challenges for kernel-level patches, and offers operational mitigations (such as disabling MSMQ) to reduce exposure until patches can be applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.