CVE-2025-26678
CVSS 3.1 Score 8.4 of 10 (high)
Details
Summary
CVE-2025-26678 is a newly disclosed vulnerability affecting Windows Defender Application Control (WDAC). The issue involves improper access control within WDAC, enabling unauthorized attackers to bypass a crucial security feature on local systems. This vulnerability could potentially allow attackers to execute unapproved applications, posing a significant risk to system security. Microsoft has not yet released a patch for this vulnerability, making it a critical concern for organizations running vulnerable Windows systems. Users are strongly advised to apply available workarounds or implement alternative security measures to mitigate this risk until a patch becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft