Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2184 articles · 154680 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-25187KEVEXPLOITEDPATCHED
microsoft · windows_10_1607

Winlogon Elevation of Privilege Vulnerability

Description

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftwindows_10_160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.25398.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
hitachihitachi storagecert_advisory90%
microsoftmicrosoft windowscert_advisory90%
microsoftwindowscert_advisory90%
microsoftmicrosoft windows server 2012 r2cert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25187(vendor-advisory, patch)

Related News (1 articles)

Tier B
BSI Advisories10h ago
[UPDATE] [hoch] Microsoft Windows und Windows Server: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.0.14393.895710.0.17763.851110.0.19044.705810.0.19045.705810.0.22631.678310.0.26100.797910.0.26200.797910.0.28000.171910.0.20348.483010.0.25398.220710.0.26100.32463
CWECWE-59
PublishedMar 10, 2026
Last enriched48d ago
Trending Score97
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-33825EXPKEV
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 149
HIGHCVE-2026-42897EXPKEV
Microsoft Exchange Server Spoofing Vulnerability
Trending: 123
HIGHCVE-2026-41091EXPKEV
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 110
MEDIUMCVE-2026-45498EXPKEV
Microsoft Defender Denial of Service Vulnerability
Trending: 91
MEDIUMCVE-2026-45585EXP
Windows BitLocker Security Feature Bypass Vulnerability
Trending: 88

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 10, 2026
Added to CISA KEV
Mar 10, 2026
Discovered by ZDM
Apr 1, 2026
Actively Exploited
Apr 14, 2026
Patch Available
Apr 14, 2026