Description
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.
Reserved 2025-02-12 | Published 2025-03-11 | Updated 2025-03-12 | Assigner
microsoftHIGH: 7.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Problem types
CWE-122: Heap-based Buffer Overflow
Product status
10.0.17763.0 before 10.0.17763.6893
affected
10.0.17763.0 before 10.0.17763.6893
affected
10.0.17763.0 before 10.0.17763.6893
affected
10.0.20348.0 before 10.0.20348.3207
affected
10.0.19043.0 before 10.0.19044.5487
affected
10.0.22621.0 before 10.0.22621.4890
affected
10.0.19045.0 before 10.0.19045.5487
affected
10.0.26100.0 before 10.0.26100.3194
affected
10.0.22631.0 before 10.0.22631.4890
affected
10.0.22631.0 before 10.0.22631.4890
affected
10.0.25398.0 before 10.0.25398.1425
affected
10.0.26100.0 before 10.0.26100.3194
affected
10.0.26100.0 before 10.0.26100.3194
affected
10.0.10240.0 before 10.0.10240.20915
affected
10.0.14393.0 before 10.0.14393.7785
affected
10.0.14393.0 before 10.0.14393.7785
affected
10.0.14393.0 before 10.0.14393.7785
affected
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26634 (Windows Core Messaging Elevation of Privileges Vulnerability) vendor-advisory
cve.org (CVE-2025-26634)
nvd.nist.gov (CVE-2025-26634)
Download JSON