← back
CVE-2025-23120

CVE-2025-23120

CVSS 9.9 CRITICALEPSS 18.3%CWE-502
Vexday Risk Score
33Attention
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 18.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In short

A critical flaw allows attackers to run arbitrary code on computers within a network domain. This puts all connected machines at serious risk of being compromised.

Technical detail

CWE-502 (Deserialization of Untrusted Data) enables remote code execution for domain-authenticated users through unsafe deserialization mechanisms. An attacker with domain access can craft malicious serialized objects to achieve arbitrary code execution on target systems.

Summary generated and translated by AI from the official description.
A vulnerability allowing remote code execution (RCE) for domain users.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →