CVE-2025-21420 — Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5052040 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 5052040 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5052006 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5052006 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5052000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5052000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5051974 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5051974 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5051974 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5051974 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5051974 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5051974 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5051989 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5051989 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5051989 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5051989 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Elevation of Privilege 5050009 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows 11 Version 24H2 for x64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Elevation of Privilege 5050009 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows Server 2012 | 5052020 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5052020 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5052042 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5052042 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5052006 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5052006 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5052000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5052000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Elevation of Privilege 5049983 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022 (Server Core installation) 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Elevation of Privilege 5049983 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5051980 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5052040 |
Security Update | Yes |
5052006 |
Security Update | Yes |
5052000 |
Security Update | Yes |
5051974 |
Security Update | Yes |
5051989 |
Security Update | Yes |
5052020 |
Monthly Rollup | Yes |
5052042 |
Monthly Rollup | Yes |
5051980 |
Security Update | Yes |
Patch Diff
cleanmgr.exe (run by the privileged SilentCleanup task) gains a SetProcessMitigationPolicy(ProcessRedirectionTrustPolicy=0x10) call in WinMainT, enabling Redirection Guard so the kernel refuses to follow attacker-planted junctions during cleanup. This severs the arbitrary folder-contents-delete -> C:\Config.msi -> SYSTEM EoP primitive (CWE-59 link following). Gated behind WIL CFR Feature_3318489400; the call hard-fails the process if the policy cannot be applied. The import itself is absent from the vulnerable 1882 build.
| Function | Address | Change | Note |
|---|---|---|---|
__GSHandlerCheck |
1400122e4 -> 140016034 |
refcount, address | similarity 1.0 |
wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> |
1400038d8 -> 140003a44 |
refcount, address, calling | similarity 1.0 |
wil::details_abi::SemaphoreValue::CreateFromValueInternal |
140003c1c -> 140003d4c |
refcount, address, calling, called | similarity 0.98 |
wil::details::WilFailureNotifyWatchers |
140005afc -> 140005c7c |
code, length, address | similarity 0.89 |
wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::reset |
140005c78 -> 140005e00 |
refcount, address, calling | similarity 1.0 |
wil::mutex_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>::acquire |
140005ba0 -> 140005d28 |
refcount, address, calling | similarity 1.0 |
wil::details::GetLastErrorFailHr |
1400042b8 -> 140004428 |
refcount, address, calling | similarity 1.0 |
operator_delete |
140005dc4 -> 140006620 |
refcount, address, calling | similarity 1.0 |
wil::details::in1diag3::FailFast_Unexpected |
140003d44 -> 140003e9c |
code, length, address | similarity 0.86 |
wil::last_error_context::last_error_context |
140003738 -> 140003834 |
refcount, address, calling | similarity 1.0 |
MSVCRT.DLL::memcpy_s |
EXTERNAL:00000028 -> EXTERNAL:0000002b |
refcount, address, calling | similarity 1.0 |
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive |
EXTERNAL:00000074 -> EXTERNAL:00000070 |
refcount, address, calling | similarity 1.0 |
atexit |
140002920 -> 140002a20 |
refcount, address, calling | similarity 1.0 |
API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree |
EXTERNAL:0000005c -> EXTERNAL:0000005d |
refcount, address, calling | similarity 1.0 |
wil::TraceLoggingProvider::Initialize |
140008890 -> 14000a020 |
refcount, address | similarity 1.0 |
StringCchPrintfW |
14000570c -> 14000581c |
refcount, address, calling | similarity 1.0 |
API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentProcessId |
EXTERNAL:00000058 -> EXTERNAL:00000056 |
refcount, address, calling | similarity 1.0 |
wil::details::in1diag3::Return_Hr |
140005358 -> 140005418 |
refcount, address, calling | similarity 1.0 |
wil::details_abi::ProcessLocalStorage<struct_wil::details_abi::ProcessLocalData>::~ProcessLocalStorage<struct_wil::details_abi::ProcessLocalData> |
140003764 -> 140003860 |
code, length, address, called | similarity 0.2 |
_purecall |
1400071c0 -> 14000a660 |
refcount, address | similarity 1.0 |
API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap |
EXTERNAL:0000005a -> EXTERNAL:0000005e |
refcount, address, calling | similarity 1.0 |
WinMainT |
140006614 -> 14000955c |
code, length, address, called | similarity 0.25 |
wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire |
140003964 -> 140003ad0 |
code, length, address, called | similarity 0.63 |
wil::details::FreeProcessHeap |
140003dc0 -> 140003f30 |
refcount, address, calling | similarity 0.9 |
wil::details::ProcessHeapAlloc |
140004f78 -> 1400050e8 |
refcount, address, calling | similarity 1.0 |
wil::details_abi::SemaphoreValue::~SemaphoreValue |
140003918 -> 140003a84 |
refcount, address, calling | similarity 1.0 |
wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::ReleaseMutex(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,2>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::ReleaseMutex(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,2>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> |
1400038f8 -> 140003a64 |
refcount, address, calling | similarity 1.0 |
USER32.DLL::LoadIconW |
EXTERNAL:00000016 |
refcount, calling | similarity 1.0 |
wil::details::ReportFailure_Hr<3> |
1400032f8 -> 1400033f8 |
code, refcount, length, address, calling | similarity 0.84 |
wil_details_GetNtDllProcedureAddress |
140005d60 -> 140005f44 |
refcount, address, calling | similarity 0.91 |
wil::last_error_context::~last_error_context |
140003940 -> 140003aac |
refcount, address, calling | similarity 1.0 |
__security_check_cookie |
1400123c0 -> 140016110 |
refcount, address, calling | similarity 1.0 |
wil::details::`dynamic_initializer_for_'g_header_init_WilInitialize_ResultMacros_DesktopOrSystem'' |
1400024d0 |
code, length | similarity 0.95 |
memset |
140012376 -> 1400160d2 |
refcount, address, calling | similarity 0.89 |
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexExW |
EXTERNAL:00000077 -> EXTERNAL:0000007b |
refcount, address, calling | similarity 1.0 |
wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> |
140009a20 -> 14000635c |
refcount, address, calling | similarity 1.0 |
__chkstk |
140012480 -> 1400161d0 |
refcount, address, calling | similarity 1.0 |
_guard_dispatch_icall$thunk$10345483385596137414 |
140013010 -> 140017010 |
refcount, address, calling | similarity 0.89 |
wil_details_GetKernelBaseProcAddress |
140005ccc -> 140005ea8 |
code, refcount, length, address, calling | similarity 0.94 |
wistd::__throw_bad_function_call |
140005b74 -> 140005cfc |
name, fullname, refcount, sig, address, calling, parent | similarity 1.0 |
wil::details_abi::SemaphoreValue::TryGetPointer |
140005818 -> 140005928 |
code, name, fullname, refcount, length, sig, address, calling, called | similarity 0.15 |
wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_3318489400>::__private_IsEnabled |
1400071e8 -> 140009fe4 |
code, name, fullname, refcount, length, sig, address, calling, called, parent | similarity 0.29 |
Attack Path
Arbitrary file deletion as SYSTEM by pointing a Disk Cleanup target at a junction
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
None