CVE-2025-21294
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-21294 is a remote code execution vulnerability affecting Microsoft's Digest Authentication implementation. An attacker can exploit this vulnerability by sending a maliciously crafted request to a targeted server, resulting in arbitrary code execution on the server-side. Successful exploitation could lead to significant security risks, including data theft and unauthorized system access. It is recommended that affected organizations apply the available Microsoft security patch as soon as possible to mitigate this threat. This vulnerability underscores the importance of keeping software up-to-date to protect against potential cyber attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008
- Windows Server 2022
Affected Vendors
- Microsoft