CVE-2025-21276
Published: 14 January 2025
Description
Windows MapUrlToZone Denial of Service Vulnerability
Security Summary
CVE-2025-21276 is a Denial of Service vulnerability affecting the MapUrlToZone component in Microsoft Windows operating systems. Published on January 14, 2025, it has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is associated with CWEs 191, 693, and NVD-CWE-noinfo.
The vulnerability can be exploited by an unauthenticated attacker over the network with low attack complexity and no user interaction required. Successful exploitation results in a denial of service condition, causing high impact to availability while having no impact on confidentiality or integrity.
Microsoft's Security Response Center provides detailed update guidance, including patches and mitigation recommendations, at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21276.
Details
- CWE(s)