Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2025-54101: Windows SMB Client Remote Code Execution Vulnerability

According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are low (PR:L). What does that mean for this vulnerability?

Exploitation of this vulnerability requires an authorized attacker on the domain to wait for a user to initiate a connection to a malicious server that the attacker has set up prior to the user connecting.

Microsoft Security Response Center
#vulnerability#windows#rce#samba#auth#Windows SMBv3 Client#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2025-59220: Windows Bluetooth Service Elevation of Privilege Vulnerability