Microsoft published security updates for multiple elevation of privilege vulnerabilities affecting Windows maintenance components and Azure File Sync. The disclosed issues include CVE-2025-21420 in the Windows Disk Cleanup Tool and CVE-2025-21419 in Windows Setup Files Cleanup, both listed in the Microsoft Security Update Guide as privilege escalation flaws requiring remediation through vendor patches.
Microsoft also lists CVE-2024-35253, an elevation of privilege vulnerability in Microsoft Azure File Sync, indicating that both on-premises Windows utilities and hybrid cloud file synchronization components were affected by privilege escalation risks. Organizations using these Microsoft components should prioritize validation and deployment of the relevant security updates to reduce the chance of local or authenticated attackers gaining higher privileges on affected systems.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published Security Update Guide entries for CVE-2025-21419 and CVE-2025-21420, two elevation of privilege vulnerabilities affecting Windows Setup Files Cleanup and the Windows Disk Cleanup Tool. The duplicate advisory entry for CVE-2025-21420 reflects the same Patch Tuesday disclosure event.
Microsoft published Security Update Guide information for CVE-2024-35253, an elevation of privilege vulnerability affecting Microsoft Azure File Sync. The advisory indicates the vulnerability was publicly disclosed as part of Microsoft's June 2024 security updates.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.