CVE-2025-26678

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 284

Summary

CVE-2025-26678 is a newly disclosed vulnerability affecting Windows Defender Application Control (WDAC). The issue involves improper access control within WDAC, enabling unauthorized attackers to bypass a crucial security feature on local systems. This vulnerability could potentially allow attackers to execute unapproved applications, posing a significant risk to system security. Microsoft has not yet released a patch for this vulnerability, making it a critical concern for organizations running vulnerable Windows systems. Users are strongly advised to apply available workarounds or implement alternative security measures to mitigate this risk until a patch becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft