CVE ID
CVE-2025-33053
Vulnerability Name
Microsoft Windows External Control of File Name or Path Vulnerability
- Project: Microsoft
- Product: Windows
Date
- Date Added: 2025-06-10
- Due Date: 2025-07-01
Description
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053 ; https://nvd.nist.gov/vuln/detail/CVE-2025-33053
Related Security News
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
- Microsoft fixes Surface Hub boot issues with emergency update
- Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
- Windows 11 24H2 emergency update fixes Easy Anti-Cheat BSOD issue
- Hackers exploited Windows WebDav zero-day to drop malware
- Microsoft creates separate Windows 11 24H2 update for incompatible PCs
- Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild
Top comments (0)