← back
CVE-2025-23120

CVE-2025-23120

CVSS 9.9 CRITICALEPSS 18.3%CWE-502
In short

A critical flaw allows attackers to run arbitrary code on computers within a network domain. This puts all connected machines at serious risk of being compromised.

Technical detail

CWE-502 (Deserialization of Untrusted Data) enables remote code execution for domain-authenticated users through unsafe deserialization mechanisms. An attacker with domain access can craft malicious serialized objects to achieve arbitrary code execution on target systems.

Summary generated and translated by AI from the official description.
A vulnerability allowing remote code execution (RCE) for domain users.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →