CVE-2025-21308

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 200

Summary

CVE-2025-21308 is a newWindows Themes Spoofing vulnerability that has been discovered. Maliciously crafted theme packages can be used to trick users into believing they are interacting with legitimate applications or systems. This can lead to users disclosing sensitive information or downloading malware, potentially compromising their system's security. The vulnerability affects certain versions of Microsoft Windows and requires user interaction to exploit. It is recommended that users install the latest security updates and avoid installing themes from untrusted sources to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11

Affected Vendors

  • Microsoft