CVE-2025-26687

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 416

Summary

CVE-2025-26687 is a newly discovered vulnerability affecting the Windows Win32K component, specifically in the GRFX subsystem. This issue permits an unauthorized attacker to execute a use-after-free condition over a network connection. By exploiting this vulnerability, an attacker can potentially elevate their privileges, gaining unauthorized access to sensitive information or system functionality. This can lead to serious security consequences, including data theft or system compromise. Microsoft is currently working on a patch to address this issue and users are advised to apply it as soon as it becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft