Remote Code Execution Vulnerability in Microsoft Digest Authentication
CVE-2025-21369

8.8HIGH

Key Information:

Summary

The Microsoft Digest Authentication vulnerability allows attackers to execute arbitrary code on systems using this authentication protocol. This remote code execution flaw can lead to significant compromises as it potentially enables unauthorized access and manipulation of sensitive data. Organizations utilizing Microsoft Digest Authentication should take immediate steps to mitigate associated risks by applying security updates and monitoring systems for unusual activities. For in-depth information, refer to the official Microsoft advisory.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20915

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7785

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6893

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.