Microsoft Windows 11 25H2 vulnerabilities
995 known vulnerabilities affecting microsoft/windows_11_25h2.
Total CVEs
995
CISA KEV
13
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL25HIGH744MEDIUM220LOW6
Vulnerabilities
Page 24 of 50
CVE-2026-35422P3MEDIUMCVSS 6.5fixed in 10.0.26200.83902026-05-12
CVE-2026-35422 [MEDIUM] CWE-288 CVE-2026-35422: Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized atta
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2026-48573P3HIGHCVSS 7.9fixed in 10.0.26200.86552026-06-09
CVE-2026-48573 [HIGH] CWE-1329 CVE-2026-48573: No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48576P3HIGHCVSS 7.9fixed in 10.0.26200.86552026-06-09
CVE-2026-48576 [HIGH] CWE-1329 CVE-2026-48576: No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-47656P3HIGHCVSS 7.9fixed in 10.0.26200.86552026-06-09
CVE-2026-47656 [HIGH] CWE-693 CVE-2026-47656: Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a secur
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-60709P3HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-60709 [HIGH] CWE-125 CVE-2025-60709: Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-24293P3HIGHCVSS 7.8fixed in 10.0.26200.79792026-03-10
CVE-2026-24293 [HIGH] CWE-476 CVE-2026-24293: Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attac
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20832P3HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20832 [HIGH] CWE-415 CVE-2026-20832: Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerabili
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
nvd
CVE-2026-20857P3HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20857 [HIGH] CWE-822 CVE-2026-20857: Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacke
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60718P3HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-60718 [HIGH] CWE-426 CVE-2025-60718: Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate p
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838P3HIGHCVSS 7.8fixed in 10.0.26200.83902026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50152P3HIGHCVSS 7.8fixed in 10.0.26200.68992025-10-14
CVE-2025-50152 [HIGH] CWE-125 CVE-2025-50152: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55339P3HIGHCVSS 7.8fixed in 10.0.26200.68992025-10-14
CVE-2025-55339 [HIGH] CWE-125 CVE-2025-55339: Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59505P3HIGHCVSS 7.8fixed in 10.0.26200.70922025-11-11
CVE-2025-59505 [HIGH] CWE-415 CVE-2025-59505: Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20822P3HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20822 [HIGH] CWE-416 CVE-2026-20822: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23673P3HIGHCVSS 7.8fixed in 10.0.26200.79792026-03-10
CVE-2026-23673 [HIGH] CWE-125 CVE-2026-23673: Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62457P3HIGHCVSS 7.8fixed in 10.0.26200.73922025-12-09
CVE-2025-62457 [HIGH] CWE-125 CVE-2025-62457: Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevat
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62466P3HIGHCVSS 7.8fixed in 10.0.26200.73922025-12-09
CVE-2025-62466 [HIGH] CWE-476 CVE-2025-62466: Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62462P3HIGHCVSS 7.8fixed in 10.0.26200.73922025-12-09
CVE-2025-62462 [HIGH] CWE-126 CVE-2025-62462: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privilege
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62464P3HIGHCVSS 7.8fixed in 10.0.26200.73922025-12-09
CVE-2025-62464 [HIGH] CWE-126 CVE-2025-62464: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privilege
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55233P3HIGHCVSS 7.8fixed in 10.0.26200.73922025-12-09
CVE-2025-55233 [HIGH] CWE-125 CVE-2025-55233: Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privile
Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd