CVE-2025-21296
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-21296 is a critical vulnerability affecting Microsoft BranchCache, a component that improves the offline availability and performance of branch office networks. Hackers can exploit this Remote Code Execution (RCE) weakness to run arbitrary code on targeted systems, potentially leading to serious data theft or system damage. This issue arises due to insufficient input validation in BranchCache, allowing attackers to inject malicious data and gain unauthorized access. System administrators are advised to install the available patch as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008
- Windows Server 2022
Affected Vendors
- Microsoft