Microsoft Windows Information Disclosure Vulnerability in MapUrlToZone

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in the Windows MapUrlToZone function. This issue could enable an unauthorized attacker to disclose information over the network by reading portions of heap memory. The vulnerability affects all supported versions of Microsoft Windows.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, allowing attackers to access sensitive data that could be transmitted over the network.

Remediation

Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles linked within the security update guide.

Added: Oct 14, 2025, 6:40 PM
Updated: Oct 14, 2025, 9:11 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.