Use After Free Vulnerability in Windows Win32K by Microsoft
CVE-2025-26687

7.5HIGH

Summary

A use after free vulnerability in Windows Win32K can be exploited by an unauthorized attacker to elevate privileges over a network, potentially compromising system integrity. This flaw poses significant risks, allowing malicious actors to gain unauthorized access to sensitive resources, making it essential for users and organizations to apply security updates promptly.

Affected Version(s)

Microsoft Office for Android Unknown 16.0.1 < 16.0.18730.20000

Microsoft Office for Universal Unknown 16.0.1 < 16.0.14326.22331

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20978

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.