Windows 11 25h2
by Microsoft
Source repositories
CVEs (1,186)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32181 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | ||
| CVE-2026-32085 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32084 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32081 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32079 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-27931 | Med | 0.36 | 5.5 | 0.01 | Apr 14, 2026 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-27930 | Med | 0.36 | 5.5 | 0.01 | Apr 14, 2026 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-20806 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. | ||
| CVE-2026-25186 | Med | 0.36 | 5.5 | 0.01 | Mar 10, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-25180 | Med | 0.36 | 5.5 | 0.01 | Mar 10, 2026 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-24282 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2026 | Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20939 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20937 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20932 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20862 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20839 | Med | 0.36 | 5.5 | 0.00 | Jan 13, 2026 | Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20838 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20835 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20829 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20827 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. |
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
Page 38 of 60