CVE-2025-21293 Active Directory Domain Services Elevation of Privilege Vulnerability

To comprehensively address CVE-2025-21293, Microsoft has released September 2025 security update KB5065426 for Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2 for x64-based Systems, and Windows 11 Version 24H2 for ARM64-based Systems. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.
For customers running these versions of Windows and who install the HotPatch updates, Microsoft has released Hotpatch KB5065474. Customers who install the HotPatch updates should install KB5065474 to be protected from this vulnerability.
Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21293