Microsoft Windows 11 25H2 vulnerabilities
995 known vulnerabilities affecting microsoft/windows_11_25h2.
Total CVEs
995
CISA KEV
13
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL25HIGH744MEDIUM220LOW6
Vulnerabilities
Page 37 of 50
CVE-2026-50354P3HIGHCVSS 7.1fixed in 10.0.26200.88752026-07-14
CVE-2026-50354 [HIGH] CWE-416 CVE-2026-50354: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55680P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-55680 [HIGH] CWE-367 CVE-2025-55680: Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows a
Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53717P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-53717 [HIGH] CWE-807 CVE-2025-53717: Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) E
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60717P3HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-60717 [HIGH] CWE-416 CVE-2025-60717: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59515P3HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-59515 [HIGH] CWE-416 CVE-2025-59515: Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privil
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20831P3HIGHCVSS 7.0fixed in 10.0.26200.76232026-01-13
CVE-2026-20831 [HIGH] CWE-367 CVE-2026-20831: Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock a
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20869P3HIGHCVSS 7.0fixed in 10.0.26200.76232026-01-13
CVE-2026-20869 [HIGH] CWE-362 CVE-2026-20869: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21240P3HIGHCVSS 7.0fixed in 10.0.26200.77812026-02-10
CVE-2026-21240 [HIGH] CWE-367 CVE-2026-21240: Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55328P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-55328 [HIGH] CWE-362 CVE-2025-55328: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50372P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-50372 [HIGH] CWE-122 CVE-2026-50372: Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate priv
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55687P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-55687 [HIGH] CWE-362 CVE-2025-55687: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-26166P3HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-26166 [HIGH] CWE-415 CVE-2026-26166: Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27917P3HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-27917 [HIGH] CWE-416 CVE-2026-27917: Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized atta
Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59196P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-59196 [HIGH] CWE-362 CVE-2025-59196: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62469P3HIGHCVSS 7.0fixed in 10.0.26200.73922025-12-09
CVE-2025-62469 [HIGH] CWE-362 CVE-2025-62469: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45640P3HIGHCVSS 7.0fixed in 10.0.26200.86552026-06-09
CVE-2026-45640 [HIGH] CWE-416 CVE-2026-45640: Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58619P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-58619 [HIGH] CWE-416 CVE-2026-58619: Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges lo
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42825P3HIGHCVSS 7.0fixed in 10.0.26200.84572026-05-12
CVE-2026-42825 [HIGH] CWE-416 CVE-2026-42825: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21221P3HIGHCVSS 7.0fixed in 10.0.26200.76232026-01-13
CVE-2026-21221 [HIGH] CWE-362 CVE-2026-21221: Concurrent execution using shared resource with improper synchronization ('race condition') in Capab
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-48571P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-48571 [HIGH] CWE-416 CVE-2026-48571: Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
nvd