CVE-2025-1673

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 125

Summary

CVE-2025-1673 is a vulnerability affecting DNS (Domain Name System) processing. Maliciously crafted DNS packets without a payload can trigger an out-of-bounds read, leading to a crash resulting in a denial of service. Alternatively, an incorrect computation may occur, potentially allowing unauthorized access or data manipulation. This issue poses a significant risk as DNS plays a critical role in the functioning of the internet.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Zephyrproject Zephyr

Affected Vendors

  • Zephyr Project