Microsoft Windows 11 25H2 vulnerabilities
334 known vulnerabilities affecting microsoft/windows_11_25h2.
Total CVEs
334
CISA KEV
12
actively exploited
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH246MEDIUM84LOW2
Vulnerabilities
Page 11 of 17
CVE-2025-62213HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-62213 [HIGH] CWE-416 CVE-2025-62213: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60709HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-60709 [HIGH] CWE-125 CVE-2025-60709: Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60720HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-60720 [HIGH] CWE-126 CVE-2025-60720: Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59515HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-59515 [HIGH] CWE-416 CVE-2025-59515: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60715HIGHCVSS 8.0fixed in 10.0.26200.70922025-11-11
CVE-2025-60715 [HIGH] CWE-122 CVE-2025-60715: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-60721HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-60721 [HIGH] CWE-270 CVE-2025-60721: Privilege context switching error in Windows Administrator Protection allows an authorized attacker
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60710HIGHCVSS 7.8KEVfixed in 10.0.26200.70922025-11-11
CVE-2025-60710 [HIGH] CWE-59 CVE-2025-60710: Improper link resolution before file access ('link following') in Host Process for Windows Tasks all
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59514HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-59514 [HIGH] CWE-269 CVE-2025-59514: Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevat
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60704HIGHCVSS 7.5fixed in 10.0.26200.70922025-11-11
CVE-2025-60704 [HIGH] CWE-325 CVE-2025-60704: Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2025-62215HIGHCVSS 7.0KEVPoCfixed in 10.0.26200.70922025-11-11
CVE-2025-62215 [HIGH] CWE-362 CVE-2025-62215: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62218HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-62218 [HIGH] CWE-362 CVE-2025-62218: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62219HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-62219 [HIGH] CWE-362 CVE-2025-62219: Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privi
Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60718HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-60718 [HIGH] CWE-426 CVE-2025-60718: Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate p
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60708MEDIUMCVSS 6.5fixed in 10.0.26200.70922025-11-11
CVE-2025-60708 [MEDIUM] CWE-822 CVE-2025-60708: Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service lo
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
nvd
CVE-2025-62209MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-11-11
CVE-2025-62209 [MEDIUM] CWE-532 CVE-2025-62209: Insertion of sensitive information into log file in Windows License Manager allows an authorized att
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62208MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-11-11
CVE-2025-62208 [MEDIUM] CWE-532 CVE-2025-62208: Insertion of sensitive information into log file in Windows License Manager allows an authorized att
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59510MEDIUMCVSS 5.5fixed in 10.0.26200.70922025-11-11
CVE-2025-59510 [MEDIUM] CWE-59 CVE-2025-59510: Improper link resolution before file access ('link following') in Windows Routing and Remote Access
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
nvd
CVE-2025-60706MEDIUMCVSS 5.5fixed in 10.0.26200.70922025-11-11
CVE-2025-60706 [MEDIUM] CWE-125 CVE-2025-60706: Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59509MEDIUMCVSS 5.5fixed in 10.0.26200.70922025-11-11
CVE-2025-59509 [MEDIUM] CWE-201 CVE-2025-59509: Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59513MEDIUMCVSS 5.5fixed in 10.0.26200.70922025-11-11
CVE-2025-59513 [MEDIUM] CWE-125 CVE-2025-59513: Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to discl
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
nvd