CVE-2025-33053
- EPSS 50.28%
- Veröffentlicht 10.06.2025 17:02:31
- Zuletzt bearbeitet 27.10.2025 17:12:46
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Internet Shortcut Files Remote Code Execution Vulnerability
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
10.06.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability
SchwachstelleWeb Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 50.28% | 0.979 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
The product allows user input to control or influence paths or file names that are used in filesystem operations.