CVE-2025-21329

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 41

Summary

CVE-2025-21329 is a security vulnerability affecting MapUrlToZone, a feature designed to help secure URLs in certain software. The flaw allows an attacker to bypass this security mechanism, potentially exposing the system to malicious URLs that should have been blocked. An attacker could exploit this vulnerability by crafting a specially crafted URL, resulting in unintended trust and execution of malicious content, leading to potential data breaches or system compromise. Organizations using the affected software are advised to apply the available patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft