CVE-2025-21185
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-21185 is an elevation of privilege vulnerability affecting Microsoft Edge, the Chromium-based web browser. Successful exploitation of this vulnerability allows an attacker to gain higher privileges on the affected system. The exact cause of the issue has not been disclosed, but it is believed to lie within the Microsoft Edge rendering engine. An attacker could potentially abuse this vulnerability by tricking a user into visiting a malicious website or opening a specially crafted file. Once exploited, an attacker could gain unrestricted access to the affected system and install malware, steal sensitive data, or perform other malicious actions. Users are encouraged to install the available patch from Microsoft as soon as possible to protect against this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Edge
Affected Vendors
- Microsoft