Remote Code Execution Vulnerability in Microsoft Digest Authentication
CVE-2025-21369
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 11 February 2025
Summary
The Microsoft Digest Authentication vulnerability allows attackers to execute arbitrary code on systems using this authentication protocol. This remote code execution flaw can lead to significant compromises as it potentially enables unauthorized access and manipulation of sensitive data. Organizations utilizing Microsoft Digest Authentication should take immediate steps to mitigate associated risks by applying security updates and monitoring systems for unusual activities. For in-depth information, refer to the official Microsoft advisory.
Affected Version(s)
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20915
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7785
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6893
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved