Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.0 (custom) before 10.0.20348.3807
affected
10.0.22621.0 (custom) before 10.0.22621.5472
affected
10.0.26100.0 (custom) before 10.0.26100.4349
affected
10.0.22631.0 (custom) before 10.0.22631.5472
affected
10.0.22631.0 (custom) before 10.0.22631.5472
affected
10.0.25398.0 (custom) before 10.0.25398.1665
affected
10.0.26100.0 (custom) before 10.0.26100.4349
affected
10.0.26100.0 (custom) before 10.0.26100.4349
affected
Description
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
Problem types
CWE-401: Missing Release of Memory after Effective Lifetime
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29828 (Windows Schannel Remote Code Execution Vulnerability)