CVE 5.4 MEDIUM

DLL hijacking of all PE32 executables on Windows 11 for ARM CPUs_CVE-2025-7676

5.4 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.

Basic Information

ID CVE-2025-7676
Source Dragos
Published Jul 28, 2025 at 16:34
Modified Jul 28, 2025 at 17:18

Affected Product

Vendor Microsoft, Inc
Product Windows 11
Affected Versions Microsoft, Inc Windows 11 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.