cbcvebase.

Microsoft Windows 11 25H2 vulnerabilities

995 known vulnerabilities affecting microsoft/windows_11_25h2.

Total CVEs
995
CISA KEV
13
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL25HIGH744MEDIUM220LOW6

Vulnerabilities

Page 40 of 50
CVE-2026-55144P3HIGHCVSS 7.1fixed in 10.0.26200.88752026-07-14
CVE-2026-55144 [HIGH] CWE-325 CVE-2026-55144: Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering l Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
nvd
CVE-2025-58730P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-58730 [HIGH] CWE-416 CVE-2025-58730: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58731P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-58731 [HIGH] CWE-416 CVE-2025-58731: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58738P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-58738 [HIGH] CWE-416 CVE-2025-58738: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58736P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-58736 [HIGH] CWE-416 CVE-2025-58736: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58734P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-58734 [HIGH] CWE-416 CVE-2025-58734: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58733P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-58733 [HIGH] CWE-416 CVE-2025-58733: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62218P3HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-62218 [HIGH] CWE-362 CVE-2025-62218: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47648P3HIGHCVSS 7.0fixed in 10.0.26200.86552026-06-09
CVE-2026-47648 [HIGH] CWE-426 CVE-2026-47648: Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50297P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-50297 [HIGH] CWE-284 CVE-2026-50297: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50325P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-50325 [HIGH] CWE-284 CVE-2026-50325: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34341P3HIGHCVSS 7.0fixed in 10.0.26200.83902026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59205P3HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-59205 [HIGH] CWE-362 CVE-2025-59205: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25184P3HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-25184 [HIGH] CWE-362 CVE-2026-25184: Concurrent execution using shared resource with improper synchronization ('race condition') in Applo Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32086P3HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-32086 [HIGH] CWE-362 CVE-2026-32086: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32150P3HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-32150 [HIGH] CWE-362 CVE-2026-32150: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54991P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-54991 [HIGH] CWE-125 CVE-2026-54991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50356P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-50356 [HIGH] CWE-362 CVE-2026-50356: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49806P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-49806 [HIGH] CWE-362 CVE-2026-49806: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54996P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-54996 [HIGH] CWE-125 CVE-2026-54996: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 11 25H2 vulnerabilities | cvebase