Microsoft Windows 11 25H2 vulnerabilities
995 known vulnerabilities affecting microsoft/windows_11_25h2.
Total CVEs
995
CISA KEV
13
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL25HIGH744MEDIUM220LOW6
Vulnerabilities
Page 44 of 50
CVE-2026-20806P4MEDIUMCVSS 5.5fixed in 10.0.26200.82462026-04-14
CVE-2026-20806 [MEDIUM] CWE-843 CVE-2026-20806: Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized at
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50483P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50483 [MEDIUM] CWE-200 CVE-2026-50483: Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55334P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-10-14
CVE-2025-55334 [MEDIUM] CWE-312 CVE-2025-55334: Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypa
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-49180P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-49180 [MEDIUM] CWE-59 CVE-2026-49180: Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll)
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50383P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50383 [MEDIUM] CWE-126 CVE-2026-50383: Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose infor
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49801P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-49801 [MEDIUM] CWE-908 CVE-2026-49801: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-40422P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-40422 [MEDIUM] CWE-908 CVE-2026-40422: Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose inf
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49177P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-49177 [MEDIUM] CWE-125 CVE-2026-49177: Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
nvd
CVE-2026-54997P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-54997 [MEDIUM] CWE-908 CVE-2026-54997: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50300P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50300 [MEDIUM] CWE-125 CVE-2026-50300: Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose i
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50381P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50381 [MEDIUM] CWE-843 CVE-2026-50381: Access of resource using incompatible type ('type confusion') in Composite Image File System Driver
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50495P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50495 [MEDIUM] CWE-284 CVE-2026-50495: Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-58614P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-58614 [MEDIUM] CWE-125 CVE-2026-58614: Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature loca
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-58545P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-58545 [MEDIUM] CWE-284 CVE-2026-58545: Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-58638P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-58638 [MEDIUM] CWE-325 CVE-2026-58638: Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50303P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50303 [MEDIUM] CWE-1240 CVE-2026-50303: Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authoriz
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-60708P4MEDIUMCVSS 6.5fixed in 10.0.26200.70922025-11-11
CVE-2025-60708 [MEDIUM] CWE-822 CVE-2025-60708: Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service lo
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
nvd
CVE-2025-59284P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-10-14
CVE-2025-59284 [MEDIUM] CWE-200 CVE-2025-59284: Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized at
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2026-50485P4MEDIUMCVSS 5.7fixed in 10.0.26200.88752026-07-14
CVE-2026-50485 [MEDIUM] CWE-126 CVE-2026-50485: Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent n
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2026-20932P4MEDIUMCVSS 5.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20932 [MEDIUM] CWE-200 CVE-2026-20932: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd