CVE-2025-21342
Published: 06 February 2025
Summary
CVE-2025-21342 is a high-severity Type Confusion (CWE-843) vulnerability in Microsoft Edge Chromium. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Client Execution (T1203); ranked in the top 24.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 RA-5 (Vulnerability Monitoring and Scanning) and SI-2 (Flaw Remediation).
Threat & Defense at a Glance
Threat & Defense Details
Mitigating Controls (NIST 800-53 r5)AI
Requires timely identification, reporting, and correction of flaws like CVE-2025-21342 in Microsoft Edge through vendor patches.
Mandates vulnerability scanning and monitoring to identify and remediate systems affected by the Edge RCE vulnerability CVE-2025-21342.
Deploys malicious code protection mechanisms to block or detect exploits targeting the remote code execution vulnerability in Chromium-based Edge.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
CVE describes RCE in Microsoft Edge browser requiring user interaction over network, directly enabling client-side exploitation (T1203) and user execution via malicious link (T1204.001).
NVD Description
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Deeper analysisAI
CVE-2025-21342 is a Remote Code Execution vulnerability in Microsoft Edge, the Chromium-based web browser. Published on 2025-02-06T23:15:09.363, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-843 and NVD-CWE-noinfo.
Remote attackers can exploit this vulnerability over the network with low complexity and no required privileges, though user interaction is necessary. Successful exploitation enables high-impact effects on confidentiality, integrity, and availability, allowing arbitrary code execution within the context of the affected browser process.
The Microsoft Security Response Center advisory provides details on mitigation and patches at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21342.
Details
- CWE(s)