CVE-2025-33053
KEVHIGH 8.8EPSS 85.4%
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 85.35% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-06-10
- Published
- 2025-06-10
- Updated
- 2026-02-26
Proof-of-concept exploits (7)
- https://www.vicarius.io/vsociety/posts/cve-2025-33053-mitigation-script-remote-code-execu…
- 4n4s4zi/CVE-2025-33053_PoC1★ · 2025-08-23
- DevBuiHieu/CVE-2025-33053-Proof-Of-Concept63★ · 2025-06-17
- TheTorjanCaptain/CVE-2025-33053-Checker-PoC1★ · 2025-06-18
- kra1t0/CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept3★ · 2025-06-19
- veath1/LNK-File-WEBDAV-Remote-Code-Execution-Vulnerability5★ · 2025-08-24
- Cyberw1ng/CVE-2025-33053-POC