Windows 11 25h2

Vendor:

First CVE: Jun 5, 2025 · Active for 1 year

996
Total CVEs
More Total CVEs than 100% of tracked products
498.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
1.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows 11 25h2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2025
13 months ago
Most Recent CVE
Jul 16, 2026
12 days ago

CVE Severity & Scoring

Windows 11 25h2996 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local771 (77.4%)
Network175 (17.6%)
Unknown0 (0.0%)
Physical35 (3.5%)
Adjacent Network15 (1.5%)
Attack Complexity
Low739 (74.2%)
High257 (25.8%)
Unknown0 (0.0%)
User Interaction
None890 (89.4%)
Unknown0 (0.0%)
Required106 (10.6%)
Privileges Required
Low739 (74.2%)
High22 (2.2%)
None235 (23.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (996 CVEs).

996 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Apr 14, 20264.393YESYES
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Feb 10, 20268.884YESNO
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Feb 10, 20268.881YESNO
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Nov 11, 20257.080YESYES
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Apr 14, 20269.874NONO
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Feb 10, 20267.873YESNO
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
Nov 11, 20257.873YESNO
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming r
Oct 14, 20257.872YESNO
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Oct 14, 20257.871YESNO
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Feb 10, 20267.870YESNO

Exploit Exposure

Signals from CVEs in this product scope (996 CVEs).

CISA KEV
13 CVEs
1.3% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
0.7% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (996 CVEs).

Media Mentions

Signals from CVEs in this product scope (996 CVEs).

Top CNAs Publishing CVEs For Windows 11 25h2

Top CWEs

Versions

No cataloged versions.