CVE-2025-21332
Published: 14 January 2025
Description
MapUrlToZone Security Feature Bypass Vulnerability
Security Summary
CVE-2025-21332 is a MapUrlToZone Security Feature Bypass Vulnerability, published on 2025-01-14. It affects Microsoft software components managed under the Microsoft Security Response Center (MSRC). The vulnerability carries a CVSS v3.1 base score of 4.3 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) and is linked to CWE-41, with additional NVD-CWE-noinfo classification.
An unauthenticated network-based attacker can exploit this vulnerability by leveraging low-complexity techniques that require user interaction, such as clicking a specially crafted link. Successful exploitation enables the attacker to bypass the MapUrlToZone security feature, resulting in low-impact confidentiality disclosure without affecting integrity or availability.
Microsoft's advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21332 provides details on mitigation, including available patches and update guidance for affected systems.
Details
- CWE(s)