CVE-2025-21185
published 2025-01-17CVE-2025-21185: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.80%
52.9th percentile
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 132.0.2957.115 | 132.0.2957.115 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 132.0.2957.115 | 132.0.2957.115 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
vendor_msrc·2025-01-14·CVSS 6.5
CVE-2025-21185 [MEDIUM] CWE-284 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could achieve elevation of privilege and gain the ability to read the API component.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), but lead to no loss of integrity (I:N) or availability (A:N). What does that mean for this vulnerability?
An attacker who successfully exploits thi
GHSA
GHSA-vvqc-c7cm-52wp: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
ghsa_unreviewed·2025-01-17
CVE-2025-21185 [MEDIUM] CWE-284 GHSA-vvqc-c7cm-52wp: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-17
Published