CVE-2025-21295
Published: 14 January 2025
Description
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Security Summary
CVE-2025-21295 is a Remote Code Execution vulnerability in the SPNEGO Extended Negotiation (NEGOEX) Security Mechanism, published on 2025-01-14. It carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-416, with additional NVD-CWE-noinfo mapping. The vulnerability affects the NEGOEX security mechanism, as detailed in the Microsoft Security Response Center advisory.
Attackers can exploit this vulnerability over the network without authentication privileges or user interaction, though it requires high attack complexity. Successful exploitation enables remote code execution with high impacts on confidentiality, integrity, and availability in the security context.
The Microsoft update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21295 provides details on affected software, exploitation status, and recommended mitigations or patches.
Details
- CWE(s)