CVE-2025-7676

MEDIUM

PE32 Executables - RCE

Title source: llm
STIX 2.1

Description

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.

Scores

CVSS v4 5.4
EPSS 0.0003
EPSS Percentile 9.7%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
Microsoft, Inc/Windows 11 < 24H2
Published Jul 28, 2025
Tracked Since Feb 18, 2026