CVE-2025-21247
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-21247 is a newly identified vulnerability in Windows MapUrlToZone functionality. It allows an unauthorized attacker to bypass security features over a network due to improper resolution of path equivalence. An attacker can potentially gain elevated privileges or access sensitive information by exploiting this vulnerability. The impact of this issue can lead to serious security consequences if left unaddressed. Microsoft recommends applying the latest security updates to mitigate this risk. Organizations should prioritize patching affected systems to protect against potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.