cbcvebase.

Microsoft Windows 11 25H2 vulnerabilities

995 known vulnerabilities affecting microsoft/windows_11_25h2.

Total CVEs
995
CISA KEV
13
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL25HIGH744MEDIUM220LOW6

Vulnerabilities

Page 41 of 50
CVE-2026-49802P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-49802 [HIGH] CWE-362 CVE-2026-49802: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49784P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-49784 [HIGH] CWE-362 CVE-2026-49784: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54111P3HIGHCVSS 7.0fixed in 10.0.26200.88752026-07-14
CVE-2026-54111 [HIGH] CWE-125 CVE-2026-54111: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50492P3MEDIUMCVSS 6.8fixed in 10.0.26200.88752026-07-14
CVE-2026-50492 [MEDIUM] CWE-122 CVE-2026-50492: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2025-62219P4HIGHCVSS 7.0fixed in 10.0.26200.70922025-11-11
CVE-2025-62219 [HIGH] CWE-362 CVE-2025-62219: Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privi Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55696P4HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-55696 [HIGH] CWE-367 CVE-2025-55696: Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) all Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27929P4HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-27929 [HIGH] CWE-367 CVE-2026-27929: Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45487P4HIGHCVSS 7.0fixed in 10.0.26200.86552026-06-09
CVE-2026-45487 [HIGH] CWE-367 CVE-2026-45487: Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49168P4MEDIUMCVSS 6.8fixed in 10.0.26200.88752026-07-14
CVE-2026-49168 [MEDIUM] CWE-190 CVE-2026-49168: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-49804P3MEDIUMCVSS 6.6fixed in 10.0.26200.88752026-07-14
CVE-2026-49804 [MEDIUM] CWE-122 CVE-2026-49804: Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate pr Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-27925P4MEDIUMCVSS 6.5fixed in 10.0.26200.82462026-04-14
CVE-2026-27925 [MEDIUM] CWE-416 CVE-2026-27925: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2026-49165P4HIGHCVSS 7.1fixed in 10.0.26200.88752026-07-14
CVE-2026-49165 [HIGH] CWE-908 CVE-2026-49165: Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50465P4HIGHCVSS 7.1fixed in 10.0.26200.88752026-07-14
CVE-2026-50465 [HIGH] CWE-284 CVE-2026-50465: Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-26152P4HIGHCVSS 7.0fixed in 10.0.26200.82462026-04-14
CVE-2026-26152 [HIGH] CWE-922 CVE-2026-26152: Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59195P4HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-59195 [HIGH] CWE-362 CVE-2025-59195: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
nvd
CVE-2025-59261P4HIGHCVSS 7.0fixed in 10.0.26200.68992025-10-14
CVE-2025-59261 [HIGH] CWE-367 CVE-2025-59261: Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authoriz Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50298P4MEDIUMCVSS 6.8fixed in 10.0.26200.88752026-07-14
CVE-2026-50298 [MEDIUM] CWE-190 CVE-2026-50298: Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate p Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-21265P4MEDIUMCVSS 6.4fixed in 10.0.26200.76232026-01-13
CVE-2026-21265 [MEDIUM] CWE-1329 CVE-2026-21265: Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificate Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The ope
nvd
CVE-2026-49174P3MEDIUMCVSS 6.1fixed in 10.0.26200.88752026-07-14
CVE-2026-49174 [MEDIUM] CWE-306 CVE-2026-49174: Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-45658P4MEDIUMCVSS 6.8fixed in 10.0.26200.86552026-06-09
CVE-2026-45658 [MEDIUM] CWE-284 CVE-2026-45658: Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
nvd
Microsoft Windows 11 25H2 vulnerabilities | cvebase