CVE-2025-21504
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2025-21504 is a newly identified vulnerability affecting Oracle MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. This issue, residing in the Optimizer component, is classified as easily exploitable. A high privileged attacker with network access can exploit it via multiple protocols, leading to a hang or frequent crashes of the MySQL Server. The result is a denial of service (DoS) attack, with a CVSS 3.1 Base Score of 4.9. Attackers can take advantage of this vulnerability without user interaction, and it does not require any UI exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MySQL