CVE-2026-25187Disclosure(microsoft / windows_10_1607)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-11); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-16: 3Mentions · 2026-03-27: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-16: 3Technical Details · 2026-03-27: 1Technical Details · 2026-05-19: 103-1103-1603-2705-19
Signal classification3 categories
Disclosure
450.0%
Patch
337.5%
General
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure1General1Patch1
2026-03-163
Disclosure3
2026-03-271
Patch1
2026-05-191
Patch1
Full discourse8 posts
  • 0patch@0patch
    Patch

    Micropatches released for Windows Accessibility Infrastructure Elevation of Privilege Vulnerability (CVE-2026-24291, CVE-2026-25186, CVE-2026-25187) https://blog.0patch.com/2026/05/micropatches-released-for-windows.html https://t.co/1be3lEyUD2

    Post summary

    The blog post announces the release of micron patches addressing three Windows Accessibility Infrastructure elevation‑of‑privilege vulnerabilities (CVE‑2026‑24291, CVE‑2026‑25186, CVE‑2026‑25187).

    140102985
    8.4K followersView on X
  • Casey Cannady@casey_cannady
    Disclosure

    Google's Project Zero just handed Microsoft a receipt. CVE-2026-25187 is a Winlogon flaw that lets a low-priv attacker walk straight to SYSTEM... no clicks, no help needed. It's March Patch Tuesday. 80+ CVEs. 55% are priv-esc bugs. Six rated "exploitation more likely." #InfoSec https://t.co/dXuhISTyBQ

    Post summary

    The tweet announces CVE-2026-25187, a low‑privilege to SYSTEM Winlogon flaw disclosed by Project Zero and highlighted on March Patch Tuesday, but contains no proof of exploitation or PoC.

    2000056
    245 followersView on X
  • VisionSEC - AI Cybersecurity@visions3c
    Patch

    @casey_cannady CVE-2026-25187 is exactly why privilege escalation monitoring matters. Low-priv to SYSTEM without user interaction is a dream path for post-exploitation. This Patch Tuesday is a reminder that Windows endpoint hygiene isn't optional — it's survival.

    Post summary

    The tweet highlights CVE‑2026‑25187 as a low‑privilege escalation flaw that can elevate to SYSTEM and urges patching via Microsoft Patch Tuesday, with no mention of exploits, PoC, or active attacks.

    0001047
    22 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft (つづき) ・CVE-2026-24291 7.8 Windows ユーザー補助インフラストラクチャ (ATBroker.exe) ・CVE-2026-24294 7.8 Windows SMB サーバー ・CVE-2026-25187 7.8 Winlogon ・CVE-2026-26132 7.8 Windows カーネル

    Post summary

    The tweet lists four Windows CVEs with a CVSS score of 7.8 and affected components, but provides no additional details about PoC, exploitation, or mitigation.

    1000079
    89 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🔐 Winlogon memory corruption (CVE-2026-25187) Google Project Zero: High-sev local priv-esc (CVSS 7.8). Windows credential everywhere risk—patch endpoints. https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/ #Windows #CVE

    Post summary

    The post announces a high‑severity local privilege‑escape flaw in Winlogon (CVE‑2026‑25187) and directs readers to Microsoft’s Patch Tuesday for a remediation.

    0000051
    492 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-25187 | Winlogon Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-25187 https://t.co/v2XwbT8uIP

    Post summary

    The post appears to be a straightforward disclosure of CVE-2026-25187, indicating a Winlogon elevation of privilege vulnerability, without details on exploits, patches, or active usage.

    0000043
    2 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25187 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-25187 ----- Traducción: CVE-2026-25187 Resolución de enlaces inapropiada an… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-25187, detailing an improper link‑resolution flaw in Winlogon that permits local privilege escalation, and links to the official CVE record.

    0000037
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25187 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-25187

    Post summary

    The post announces CVE-2026-25187 as a local privilege escalation issue caused by improper link resolution in Winlogon, with no evidence of PoC, exploit code, active exploitation, or remediation steps.

    00000210
    56.7K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more