External Control of File Name or Path in Microsoft products - CVE-2025-33053
Published: June 10, 2025 / Updated: January 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to incorrect processing of file path in WebDav links. A remote attacker can trick the victim into clicking on a specially crafted link and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Windows Server
Microsoft Internet Explorer
How to mitigate CVE-2025-33053
Windows Server - addressed in versions 2008 R2 6.1.7601.27769, 2008 6.0.6003.23351, 2012 R2 6.3.9600.22620, 2012 6.2.9200.25522, 2016 10.0.14393.8148, 2019 10.0.17763.7434, 2022 23H2 10.0.25398.1665, 2022 10.0.20348.3745, 2022 10.0.20348.3807, 2025 10.0.26100.4270, 2025 10.0.26100.4349
Links to Public Exploits and PoC-codes
- Exploit #12224 - CVE-2025-33053-POC (POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploitation steps, reproducible test cases, and observable impact, helping security (January 4, 2026)
- Exploit #11778 - CPR-Zero: CVE-2025-33053 (July 9, 2025)
- Exploit #11732 - CVE-2025-33053 Exploit via Malicious .URL File and WebDAV (June 29, 2025)
- Exploit #11680 - CVE-2025-33053-Checker-PoC (June 20, 2025)
- Exploit #11660 - CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept (Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF payload and a video-only showcase of potential command-and-co (June 20, 2025)
- Exploit #11642 - CVE-2025-33053-Proof-Of-Concept (June 13, 2025)