CVE-2025-26665
CVSS 3.1 Score 7 of 10 (high)
Details
Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 591
Summary
CVE-2025-26665 is a vulnerability affecting Windows upnphost.dll. The issue involves the improper handling of memory in this component, which results in sensitive data being stored in an inadequately secured manner. An attacker who has already gained authorized access to the system can exploit this vulnerability to elevate their privileges and gain higher levels of system access locally. This flaw poses a significant risk to security, as it allows an attacker to bypass normal access restrictions and potentially gain control over the entire system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft