CVE-2025-21276

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 693
CWE ID 191

Summary

CVE-2025-21276 is a newly disclosed vulnerability affecting Windows systems. This Denial of Service (DoS) issue lies in the MapUrlToZone function, which is responsible for mapping URLs to security zones. An attacker can exploit this vulnerability by sending specially crafted URLs to a targeted system, resulting in an excessive consumption of system resources. As a consequence, the victim's system may experience degraded performance or even become unresponsive, rendering it inaccessible for legitimate users. Microsoft released a security advisory and a patch to address this vulnerability. It is highly recommended for Windows users to apply the patch promptly to mitigate the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft