CVE-2025-26687
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-26687 is a newly discovered vulnerability affecting the Windows Win32K component, specifically in the GRFX subsystem. This issue permits an unauthorized attacker to execute a use-after-free condition over a network connection. By exploiting this vulnerability, an attacker can potentially elevate their privileges, gaining unauthorized access to sensitive information or system functionality. This can lead to serious security consequences, including data theft or system compromise. Microsoft is currently working on a patch to address this issue and users are advised to apply it as soon as it becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008 R2
- Microsoft Windows
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft