PT-2025-6338 · Microsoft · Windows Disk Cleanup Tool+1

Published

2025-02-11

·

Updated

2026-02-11

·

CVE-2025-21420

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Disk Cleanup Tool (affected versions not specified)
Description A critical issue exists within the Windows Disk Cleanup Tool (cleanmgr.exe) that allows for privilege escalation to SYSTEM privileges. The flaw involves errors in handling symbolic links and enables attackers to exploit the system through DLL sideloading. This issue, identified as CVE-2025-21420, has been actively exploited and a proof-of-concept (PoC) has been released. The exploitation of this issue could allow an attacker to gain elevated privileges on a compromised system. The vulnerability was addressed by Microsoft as part of the February 2025 Patch Tuesday.
Recommendations Apply the February 2025 security updates to address this vulnerability.

Exploit

Fix

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-01894
CVE-2025-21420

Affected Products

Windows
Windows Disk Cleanup Tool