Windows 11 25h2
by Microsoft
CVEs (1,162)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-61918 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61345 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||
| CVE-2026-59138 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||
| CVE-2026-42907 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42903 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. | ||
| CVE-2026-35422 | Med | 0.42 | 6.5 | 0.01 | May 12, 2026 | Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2026-32151 | Med | 0.42 | 6.5 | 0.01 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-27925 | Med | 0.42 | 6.5 | 0.00 | Apr 14, 2026 | Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-26155 | Med | 0.42 | 6.5 | 0.01 | Apr 14, 2026 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | ||
| CVE-2026-21265 | Med | 0.42 | 6.4 | 0.01 | Jan 13, 2026 | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing… | ||
| CVE-2026-20847 | Med | 0.42 | 6.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-20812 | Med | 0.42 | 6.5 | 0.01 | Jan 13, 2026 | Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. | ||
| CVE-2025-64670 | Med | 0.42 | 6.5 | 0.01 | Dec 9, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-62473 | Med | 0.42 | 6.5 | 0.01 | Dec 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-62465 | Med | 0.42 | 6.5 | 0.00 | Dec 9, 2025 | Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | ||
| CVE-2025-62463 | Med | 0.42 | 6.5 | 0.00 | Dec 9, 2025 | Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | ||
| CVE-2025-60708 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | ||
| CVE-2025-59259 | Med | 0.42 | 6.5 | 0.01 | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | ||
| CVE-2025-59257 | Med | 0.42 | 6.5 | 0.01 | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | ||
| CVE-2025-59244 | Med | 0.42 | 6.5 | 0.01 | Oct 14, 2025 | External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.01
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- risk 0.42cvss 6.4epss 0.01
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing…
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
- risk 0.42cvss 6.5epss 0.01
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
Page 32 of 59