fkie_cve-2025-26634
Vulnerability from fkie_nvd
Published
2025-03-11 17:16
Modified
2025-07-03 15:55
Summary
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "3EC9E148-24F5-4FB0-A9FE-6098A2395D5F",
              "versionEndExcluding": "10.0.10240.20915",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
              "matchCriteriaId": "C91C224C-5CC9-42EF-8053-AC80EE2CC2B5",
              "versionEndExcluding": "10.0.14393.7785",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
              "matchCriteriaId": "07421D08-3F88-4532-B652-36825784EFF9",
              "versionEndExcluding": "10.0.14393.7785",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "A932CBA3-651F-4BBA-968A-2D6CA7DF8506",
              "versionEndExcluding": "10.0.19044.5487",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "810C8ECB-619F-447C-B352-E66F7EF5216E",
              "versionEndExcluding": "10.0.19045.5487",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "30AF7170-5722-4C9C-A8AD-7A9F0C5952EE",
              "versionEndExcluding": "10.0.22621.4890",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "62FFD367-FB8B-48CA-813F-760E4F393555",
              "versionEndExcluding": "10.0.22631.4890",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "B9C5B9BC-F08B-49F8-82D3-7CC6BDB68995",
              "versionEndExcluding": "10.0.26100.3194",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "208FA80F-F742-473E-81D5-003DC2BFFC6C",
              "versionEndExcluding": "10.0.14393.7785",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "273EE4B9-8B53-4387-98C8-EC5D2558DB82",
              "versionEndExcluding": "10.0.17763.6893",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "1711CDE0-4C93-40D3-91B7-DE507143A45F",
              "versionEndExcluding": "10.0.20348.3207",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "D3106289-A3E3-4508-B118-17BD2488D681",
              "versionEndExcluding": "10.0.25398.1425",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "70BC66D1-8679-4FA5-A4E0-2E9FDB56E273",
              "versionEndExcluding": "10.0.26100.3194",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network."
    },
    {
      "lang": "es",
      "value": "El desbordamiento del b\u00fafer basado en mont\u00f3n en Windows Core Messaging permite que un atacante autorizado eleve privilegios en una red."
    }
  ],
  "id": "CVE-2025-26634",
  "lastModified": "2025-07-03T15:55:30.563",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "HIGH",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 7.5,
          "baseSeverity": "HIGH",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 1.6,
        "impactScore": 5.9,
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  },
  "published": "2025-03-11T17:16:43.743",
  "references": [
    {
      "source": "secure@microsoft.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26634"
    }
  ],
  "sourceIdentifier": "secure@microsoft.com",
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ],
      "source": "secure@microsoft.com",
      "type": "Secondary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…