CVE-2025-26647
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 8, 2025
Updated: Apr 11, 2025
CWE ID 20
Summary
CVE-2025-26647 is a newly disclosed vulnerability that can be exploited by unauthorized attackers to elevate privileges over a network. This vulnerability lies in the Windows Kerberos system, which fails to properly validate input. An attacker who successfully exploits this weakness can gain elevated access to targeted systems, potentially causing significant damage or enabling further attacks. Organizations running affected versions of Windows are strongly advised to apply the available patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft