DLL hijacking of all PE32 executables on Windows 11 for ARM CPUs

CVE Details

Basic Information

Title DLL hijacking of all PE32 executables on Windows 11 for ARM CPUs
Type cve
Published 2025-07-28T16:34:28.584Z
Modified 2025-07-28T17:18:40.248Z

Product Information

Vendor Microsoft, Inc
Product Windows 11
Version 0

CVSS Information

Base Score 5.4 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

AI Analysis

AI Description A DLL hijacking vulnerability in Windows 11 for ARM CPUs allows attackers to execute arbitrary code by planting malicious DLLs. This issue was fixed in release 24H2 but affects all earlier versions.
AI Severity Medium
AI Vendor Microsoft, Inc
AI Product Windows 11
AI Version All versions prior to 24H2

Affected Products

  • Microsoft, Inc Windows 11 0

Additional Information

CWE List CWE-427
Source Dragos

Description

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.