Cyber Posture

CVE-2025-21342

High

Published: 06 February 2025

Published
06 February 2025
Modified
11 February 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0090 75.8th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Security Summary

CVE-2025-21342 is a Remote Code Execution vulnerability in Microsoft Edge, the Chromium-based web browser. Published on 2025-02-06T23:15:09.363, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-843 and NVD-CWE-noinfo.

Remote attackers can exploit this vulnerability over the network with low complexity and no required privileges, though user interaction is necessary. Successful exploitation enables high-impact effects on confidentiality, integrity, and availability, allowing arbitrary code execution within the context of the affected browser process.

The Microsoft Security Response Center advisory provides details on mitigation and patches at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21342.

Details

CWE(s)
CWE-843NVD-CWE-noinfo

Affected Products

microsoft
edge chromium
≤ 133.0.3065.51

References