Executive brief
A vulnerability exists in the Windows CryptoAPI, a core component responsible for handling security and encryption tasks in the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to tamper with sensitive data or bypass security protections. This could lead to a loss of data integrity or unauthorized access to confidential information on the affected system.
Technical details
A vulnerability classified as CWE-325 (Missing Cryptographic Step) exists in the Microsoft Windows CryptoAPI. The flaw is caused by the omission of a critical cryptographic verification or transformation step during data processing. An attacker with local access and low-level privileges can exploit this to perform unauthorized tampering with data or cryptographic objects. Successful exploitation could result in a high impact on confidentiality and integrity. The vulnerability affects multiple versions of Windows 11 and Windows Server, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory