CVE-2025-55232 is a critical deserialization vulnerability in Microsoft High Performance Compute Pack (HPC) that allows an unauthenticated attacker to achieve remote code execution over a network. With a CVSS score of 9.8, this flaw presents a severe risk, enabling full compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 14 mentions and 4 media articles, indicating high awareness. Organizations using Microsoft HPC Pack should prioritize patching to mitigate this high-risk vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.3.8352CPE matchmatch criteria | cpe:2.3:a:microsoft:hpc_pack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.