CVE CVE

CVE-2025-33053

CISA Known Exploited Vulnerability (KEV)

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

June 10, 2025

July 1, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

Weakness Enumeration

CWE-ID CWE Name

CWE-73
External Control of File Name or Path

Known Affected Software Configurations


cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.4270:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.6093:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7558:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7558:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6093:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6093:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.8246:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.4270:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.3981:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.8246:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5624:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.6093:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.21073:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5624:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.6093:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11_23h2:10.0.22621.5335:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.4652:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.21073:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.6093:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022_23h2:10.0.25398.1551:*:*:*:azure:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3270:*:*:*:azure:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022_23h2:10.0.25398.1551:*:*:*:datacenter:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022_23h2:10.0.25398.1551:*:*:*:standard:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3328:*:*:*:azure:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3328:*:*:*:datacenter:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3270:*:*:*:standard:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3270:*:*:*:datacenter:*:x64:*

cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.7434:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2025:10.0.26100.3476:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3807:*:*:*:standard:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3807:*:*:*:datacenter:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3807:*:*:*:azure:*:x64:*

cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.8148:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2025:10.0.26100.2605:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.3328:*:*:*:standard:*:x64:*

cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.7969:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5965:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5854:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.14393.5989:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7434:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7969:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7314:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7876:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7969:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7136:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7009:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5854:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7428:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.5189:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5965:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7970:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.21034:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.21034:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20978:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5854:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.21014:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20947:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5854:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5965:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5737:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20796:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7314:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7434:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.5335:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5737:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7009:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7136:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7876:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5854:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.4349:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.5335:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5737:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5737:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.7137:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.5189:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22631.5191:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5189:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20978:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.21014:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.20947:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5335:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5854:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_22h2:10.0.19045.5965:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.3775:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5335:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5737:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.3476:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.3476:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5189:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_21h2:10.0.19044.5011:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5191:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5191:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.6414:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.3775:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_24h2:10.0.26100.4061:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11_23h2:10.0.22631.5472:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_11_22h2:10.0.22621.5472:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.8148:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.7970:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.8066:*:*:*:*:*:x86:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
8.8
Severity:

HIGH

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2

Not defined