CVE Details
Basic Information
| Title | DLL hijacking of all PE32 executables on Windows 11 for ARM CPUs |
|---|---|
| Type | cve |
| Published | 2025-07-28T16:34:28.584Z |
| Modified | 2025-07-28T17:18:40.248Z |
Product Information
| Vendor | Microsoft, Inc |
|---|---|
| Product | Windows 11 |
| Version | 0 |
CVSS Information
| Base Score | 5.4 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
AI Analysis
| AI Description | A DLL hijacking vulnerability in Windows 11 for ARM CPUs allows attackers to execute arbitrary code by planting malicious DLLs. This issue was fixed in release 24H2 but affects all earlier versions. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Microsoft, Inc |
| AI Product | Windows 11 |
| AI Version | All versions prior to 24H2 |
Affected Products
- Microsoft, Inc Windows 11 0
Additional Information
| CWE List | CWE-427 |
|---|---|
| Source | Dragos |
Description
DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.