CVE-2025-33053HIGH 8.8CISA KEVEPSS p99.6%

CVE-2025-33053 Microsoft Windows External Control of File Name or Path Vulnerability

Microsoft / Windows

Description

Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS81.56% probability of exploitation · percentile 99.6% · 2026-06-17T12:03:21Z
Published2025-06-10
Last modified2025-10-27

CISA KEV entry

Added to KEV: 2025-06-10

Underlying weaknesses· 1

CWE-73

References

  1. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33053
  2. https://research.checkpoint.com/2025/stealth-falcon-zero-day/
  3. https://therecord.media/microsoft-cisa-zero-day-turkish-defense-org
  4. https://www.bleepingcomputer.com/news/security/stealth-falcon-hackers-exploited-windows-webdav-zero-day-to-drop-malware/
  5. https://www.darkreading.com/vulnerabilities-threats/stealth-falcon-apt-exploits-microsoft-rce-zero-day-mideast
  6. https://www.theregister.com/2025/06/10/microsoft_patch_tuesday_june/
  7. https://www.vicarius.io/vsociety/posts/cve-2025-33053-detection-script-remote-code-execution-vulnerability-in-microsoft-webdav
  8. https://www.vicarius.io/vsociety/posts/cve-2025-33053-mitigation-script-remote-code-execution-vulnerability-in-microsoft-webdav

1

TypeTargetConfidenceTier
WeaknessExternal Control of File Name or Pathcwe-730%live

(incoming)1

TypeTargetConfidenceTier
KEVEntry Microsoft Windows External Control of File Name or Path Vulnerabilitykev-cve-2025-330530%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Windows Remote Code Execution Vulnerability
CVE
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
CVE
CVE-2026-40370
CVE
Microsoft Windows Shell Remote Code Execution Vulnerability
CVE
CVE-2025-26645
CVE
CVE-2025-48817
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.