CVE-2025-26688

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 121

Summary

CVE-2025-26688 is a newly disclosed vulnerability affecting Microsoft Virtual Hard Drive. This issue involves a stack-based buffer overflow, which can be exploited by an attacker who has already gained authorized access to the system. By manipulating data and overflowing the buffer, the attacker can gain elevated privileges, potentially allowing them to take control of the affected system and perform unauthorized actions. This vulnerability poses a significant risk to organizations using Microsoft Virtual Hard Drive and highlights the importance of maintaining up-to-date software and implementing robust security measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft