Microsoft Windows 11 Version 25H2 vulnerabilities
452 known vulnerabilities affecting microsoft/windows_11_version_25h2.
Total CVEs
452
CISA KEV
11
actively exploited
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH337MEDIUM110LOW2
Vulnerabilities
Page 23 of 23
CVE-2025-59294MEDIUMCVSS 4.6≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-59294 [MEDIUM] CWE-200 CVE-2025-59294: Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unautho
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2025-59284MEDIUMCVSS 5.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-59284 [MEDIUM] CWE-200 CVE-2025-59284: Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized at
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2025-55330MEDIUMCVSS 4.6≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-55330 [MEDIUM] CWE-841 CVE-2025-55330: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-59190MEDIUMCVSS 5.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2025-59257MEDIUMCVSS 6.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-59257 [MEDIUM] CWE-1287 CVE-2025-59257: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2025-58729MEDIUMCVSS 6.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-58729 [MEDIUM] CWE-1287 CVE-2025-58729: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2025-55682MEDIUMCVSS 4.6≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-55682 [MEDIUM] CWE-841 CVE-2025-55682: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-59244MEDIUMCVSS 6.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-59244 [MEDIUM] CWE-73 CVE-2025-59244: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-59253MEDIUMCVSS 5.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-59253 [MEDIUM] CWE-284 CVE-2025-59253: Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
nvd
CVE-2025-48813MEDIUMCVSS 4.7≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-48813 [MEDIUM] CWE-324 CVE-2025-48813: Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perfor
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
nvd
CVE-2025-55325MEDIUMCVSS 5.5≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-55325 [MEDIUM] CWE-126 CVE-2025-55325: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55695LOWCVSS 3.3≥ 10.0.26200.0, < 10.0.26200.68992025-10-14
CVE-2025-55695 [LOW] CWE-125 CVE-2025-55695: Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose inf
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
nvd
← Previous23 / 23