CVE-2025-21294
Published: 14 January 2025
Description
Microsoft Digest Authentication Remote Code Execution Vulnerability
Security Summary
CVE-2025-21294 is a remote code execution vulnerability affecting Microsoft Digest Authentication. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-591.
An unauthenticated attacker can exploit this vulnerability over the network, though it requires high attack complexity and no user interaction. Successful exploitation enables remote code execution with high impacts on confidentiality, integrity, and availability.
Microsoft's Security Response Center provides an update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21294 detailing mitigation and patching information.
Details
- CWE(s)