Microsoft Windows 11 25H2 vulnerabilities
995 known vulnerabilities affecting microsoft/windows_11_25h2.
Total CVEs
995
CISA KEV
13
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL25HIGH744MEDIUM220LOW6
Vulnerabilities
Page 45 of 50
CVE-2026-20823P4MEDIUMCVSS 5.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20823 [MEDIUM] CWE-200 CVE-2026-20823: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20862P4MEDIUMCVSS 5.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20862 [MEDIUM] CWE-200 CVE-2026-20862: Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59211P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-10-14
CVE-2025-59211 [MEDIUM] CWE-200 CVE-2025-59211: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55336P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-10-14
CVE-2025-55336 [MEDIUM] CWE-200 CVE-2025-55336: Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59509P4MEDIUMCVSS 5.5fixed in 10.0.26200.70922025-11-11
CVE-2025-59509 [MEDIUM] CWE-201 CVE-2025-59509: Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20829P4MEDIUMCVSS 5.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20829 [MEDIUM] CWE-125 CVE-2026-20829: Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20835P4MEDIUMCVSS 5.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20835 [MEDIUM] CWE-125 CVE-2026-20835: Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57084P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-57084 [MEDIUM] CWE-908 CVE-2026-57084: Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose i
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-62209P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-11-11
CVE-2025-62209 [MEDIUM] CWE-532 CVE-2025-62209: Insertion of sensitive information into log file in Windows License Manager allows an authorized att
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2025-62208P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-11-11
CVE-2025-62208 [MEDIUM] CWE-532 CVE-2025-62208: Insertion of sensitive information into log file in Windows License Manager allows an authorized att
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57083P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-57083 [MEDIUM] CWE-908 CVE-2026-57083: Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-62468P4MEDIUMCVSS 5.5fixed in 10.0.26200.73922025-12-09
CVE-2025-62468 [MEDIUM] CWE-125 CVE-2025-62468: Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose in
Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59204P4MEDIUMCVSS 5.5fixed in 10.0.26200.68992025-10-14
CVE-2025-59204 [MEDIUM] CWE-908 CVE-2025-59204: Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclo
Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50389P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50389 [MEDIUM] CWE-200 CVE-2026-50389: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-56184P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-56184 [MEDIUM] CWE-200 CVE-2026-56184: Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59513P4MEDIUMCVSS 5.5fixed in 10.0.26200.70922025-11-11
CVE-2025-59513 [MEDIUM] CWE-125 CVE-2025-59513: Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to discl
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45594P4MEDIUMCVSS 5.5fixed in 10.0.26200.86552026-06-09
CVE-2026-45594 [MEDIUM] CWE-200 CVE-2026-45594: Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) S
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50420P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-50420 [MEDIUM] CWE-125 CVE-2026-50420: Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information local
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-45634P4MEDIUMCVSS 5.5fixed in 10.0.26200.86552026-06-09
CVE-2026-45634 [MEDIUM] CWE-125 CVE-2026-45634: Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information loca
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34349P4MEDIUMCVSS 5.5fixed in 10.0.26200.88752026-07-14
CVE-2026-34349 [MEDIUM] CWE-200 CVE-2026-34349: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
nvd