Aller au contenu

Fiche vulnérabilité

CVE-2025-33053 : faille exploitée microsoft windows 10 1507 (CVSS 8.8)

Description

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
10 juin 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • microsoft windows server 2022
  • microsoft windows server 2022 23h2
  • microsoft windows server 2025

Correctif et mesures

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE