Microsoft Windows 11 25H2 vulnerabilities
334 known vulnerabilities affecting microsoft/windows_11_25h2.
Total CVEs
334
CISA KEV
12
actively exploited
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH246MEDIUM84LOW2
Vulnerabilities
Page 6 of 17
CVE-2026-20919HIGHCVSS 7.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20919 [HIGH] CWE-362 CVE-2026-20919: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20931HIGHCVSS 8.0fixed in 10.0.26200.76232026-01-13
CVE-2026-20931 [HIGH] CWE-73 CVE-2026-20931: External control of file name or path in Windows Telephony Service allows an authorized attacker to
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2026-20814HIGHCVSS 7.0fixed in 10.0.26200.76232026-01-13
CVE-2026-20814 [HIGH] CWE-362 CVE-2026-20814: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20826HIGHCVSS 7.0fixed in 10.0.26200.76232026-01-13
CVE-2026-20826 [HIGH] CWE-362 CVE-2026-20826: Concurrent execution using shared resource with improper synchronization ('race condition') in Table
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20924HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20924 [HIGH] CWE-362 CVE-2026-20924: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20809HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20809 [HIGH] CWE-122 CVE-2026-20809: Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized atta
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20858HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20858 [HIGH] CWE-362 CVE-2026-20858: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20867HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20867 [HIGH] CWE-362 CVE-2026-20867: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20871HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20871 [HIGH] CWE-416 CVE-2026-20871: Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locall
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21221HIGHCVSS 7.0fixed in 10.0.26200.76232026-01-13
CVE-2026-21221 [HIGH] CWE-362 CVE-2026-21221: Concurrent execution using shared resource with improper synchronization ('race condition') in Capab
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20868HIGHCVSS 8.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20868 [HIGH] CWE-122 CVE-2026-20868: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-20923HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20923 [HIGH] CWE-416 CVE-2026-20923: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20938HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20938 [HIGH] CWE-822 CVE-2026-20938: Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an autho
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20866HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20866 [HIGH] CWE-362 CVE-2026-20866: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20859HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20859 [HIGH] CWE-416 CVE-2026-20859: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20934HIGHCVSS 7.5fixed in 10.0.26200.76232026-01-13
CVE-2026-20934 [HIGH] CWE-362 CVE-2026-20934: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-20853HIGHCVSS 7.4fixed in 10.0.26200.76232026-01-13
CVE-2026-20853 [HIGH] CWE-362 CVE-2026-20853: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-20820HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20820 [HIGH] CWE-122 CVE-2026-20820: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20874HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20874 [HIGH] CWE-362 CVE-2026-20874: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20918HIGHCVSS 7.8fixed in 10.0.26200.76232026-01-13
CVE-2026-20918 [HIGH] CWE-362 CVE-2026-20918: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd