CVE-2025-7676 MEDIUM

CVE-2025-7676: DLL hijacking of all PE32 executables on Windows 11 for ARM CPUs

Vendor Microsoft, Inc
Product Windows 11
Weakness CWE-427
Published July 28, 2025
Last update July 28, 2025

CVSS base score

5.4/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.

Key dates

02Disclosure timeline

July 28, 2025 CVE published
July 28, 2025 Record updated