CVE-2025-33053
Microsoft · Published June 10, 2025
8.8
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
Affected Products
- Windows 10 1507 < 10.0.10240.21034
- Windows 10 1607 < 10.0.14393.8148
- Windows 10 1809 < 10.0.17763.7434
- Windows 10 21h2 < 10.0.19044.5965
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H