CVE-2025-7676
DLL hijacking of all PE32 executables on Windows 11 for ARM CPUs
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.4EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
28 jul 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Microsoft, Inc · Windows 11¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →