Microsoft disclosed and patched two vulnerabilities in Internet Connection Sharing (ICS) tracked as CVE-2025-21254 and CVE-2025-21216. Both issues are classified as denial-of-service flaws in the Windows ICS component, which is used to share a system’s network connection with other devices, and were published through the company’s Security Update Guide.
The advisories provide limited public technical detail, but the pairing of two ICS DoS entries indicates that unpatched Windows systems using the feature could face service disruption if the vulnerabilities are triggered. Organizations should review Microsoft’s guidance for both CVEs, identify Windows assets with ICS enabled, and prioritize deployment of the relevant security updates to reduce the risk of network-sharing outages.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft released Security Update Guide entries for CVE-2025-21216 and CVE-2025-21254, both affecting Internet Connection Sharing (ICS) and described as denial-of-service vulnerabilities.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.