CVE-2025-29828Missing Release of Memory after Effective Lifetime in Microsoft Windows 11 Version 22h2

Severity
8.1HIGHNVD
EPSS
0.9%
top 24.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages10 packages

NVDmicrosoft/windows< 10.0.20348.3745+2
NVDmicrosoft/windows_11_22h2< 10.0.22621.5472
NVDmicrosoft/windows_11_23h2< 10.0.22631.5472
NVDmicrosoft/windows_11_24h2< 10.0.26100.4270
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.3807

🔴Vulnerability Details

2
CVEList
Windows Schannel Remote Code Execution Vulnerability2025-06-10
GHSA
GHSA-vjfq-34vr-xpmm: Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network2025-06-10

📋Vendor Advisories

1
Microsoft
Windows Schannel Remote Code Execution Vulnerability2025-06-10

🕵️Threat Intelligence

7
Talos
Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities2025-06-10
Talos
Microsoft Patch Tuesday for June 2025 — Snort rules and prominent vulnerabilities2025-06-10
Qualys
Microsoft and Adobe Patch Tuesday, June 2025 Security Update Review2025-06-10
Qualys
Microsoft and Adobe Patch Tuesday, June 2025 Security Update Review | Qualys2025-06-10
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10
CVE-2025-29828 — Microsoft vulnerability | cvebase