CVE-2025-21247

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 41

Summary

CVE-2025-21247 is a newly identified vulnerability in Windows MapUrlToZone functionality. It allows an unauthorized attacker to bypass security features over a network due to improper resolution of path equivalence. An attacker can potentially gain elevated privileges or access sensitive information by exploiting this vulnerability. The impact of this issue can lead to serious security consequences if left unaddressed. Microsoft recommends applying the latest security updates to mitigate this risk. Organizations should prioritize patching affected systems to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share