Protection Mechanism Failure in Windows Allowing Network Bypass
CVE-2025-54917

4.3MEDIUM

What is CVE-2025-54917?

A vulnerability in Windows MapUrlToZone allows unauthorized attackers to exploit a flaw in the protection mechanism, leading to a potential security feature bypass over the network. This undermines the integrity of security measures, enabling malicious entities to gain privileges that could compromise sensitive data and system operations.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21128

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8422

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7792

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54917 : Protection Mechanism Failure in Windows Allowing Network Bypass