CVE-2025-26665

CVSS 3.1 Score 7 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 591

Summary

CVE-2025-26665 is a vulnerability affecting Windows upnphost.dll. The issue involves the improper handling of memory in this component, which results in sensitive data being stored in an inadequately secured manner. An attacker who has already gained authorized access to the system can exploit this vulnerability to elevate their privileges and gain higher levels of system access locally. This flaw poses a significant risk to security, as it allows an attacker to bypass normal access restrictions and potentially gain control over the entire system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft