Microsoft Windows External Control of File Name or Path Vulnerability
High Listed in CISA KEV
Summary
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Windows
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-33053 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053 reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV