Remote Code Execution Vulnerability in Internet Explorer by Microsoft
CVE-2025-21326

7.8HIGH

Summary

This vulnerability in Internet Explorer allows an attacker to execute arbitrary code on a user’s system. By exploiting this flaw, a malicious entity can gain unauthorized access to the affected system, potentially compromising sensitive data and leading to further exploitation. Users are urged to apply security updates to mitigate risks associated with this vulnerability, which is particularly concerning given the extensive use of Internet Explorer across various platforms.

Affected Version(s)

Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 < 10.0.25398.1369

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.2894

Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.2894

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.