VDB

GCVE-110-NCSC-2025-153

GCVE-110-NCSC-2025-153
Advisory PublishedCVSS 10.0/10
Vulnetix · Advisory published May 13, 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection')

Weaknesses (CWE)

CWE-73External Control of File Name or PathCWE-1220Insufficient Granularity of Access ControlCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-552Files or Directories Accessible to External PartiesCWE-302Authentication Bypass by Assumed-Immutable Data

Risk Scores

CVSS 3.1
10.0/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/17.10|<17.13.7
Microsoftvers:microsoft/17.12.8
Microsoftvers:unknown/17.8.0|<17.8.21
Microsoftvers:microsoft/9.0.0
Microsoftvers:unknown/16.11.0|<16.11.47
Microsoftvers:unknown/15.9.0|<15.9.73
Microsoftvers:microsoft/unknown
Microsoftvers:microsoft/17.10.14
Microsoftvers:microsoft/16.11.47
Microsoftvers:microsoft/2022
Microsoftvers:unknown/17.0|<17.12.8
Microsoftvers:unknown/17.10|<17.10.14
Microsoftvers:unknown/n/a
Microsoftvers:microsoft/8.0.0
Microsoftvers:microsoft/17.13.7

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›