CVE-2025-21185

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 284

Summary

CVE-2025-21185 is an elevation of privilege vulnerability affecting Microsoft Edge, the Chromium-based web browser. Successful exploitation of this vulnerability allows an attacker to gain higher privileges on the affected system. The exact cause of the issue has not been disclosed, but it is believed to lie within the Microsoft Edge rendering engine. An attacker could potentially abuse this vulnerability by tricking a user into visiting a malicious website or opening a specially crafted file. Once exploited, an attacker could gain unrestricted access to the affected system and install malware, steal sensitive data, or perform other malicious actions. Users are encouraged to install the available patch from Microsoft as soon as possible to protect against this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share