CVE-2025-29828: Microsoft Windows 11 22h2
High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
Affected products
- Microsoft Windows 11 22h2: before 10.0.22621.5472 (fixed in 10.0.22621.5472)
- Microsoft Windows 11 23h2: before 10.0.22631.5472 (fixed in 10.0.22631.5472)
- Microsoft Windows 11 24h2: before 10.0.26100.4270 (fixed in 10.0.26100.4270)
- Microsoft Windows Server 2022: before 10.0.20348.3745 (fixed in 10.0.20348.3745)
- Microsoft Windows Server 2022 23h2: before 10.0.25398.1665 (fixed in 10.0.25398.1665)
- Microsoft Windows Server 2025: before 10.0.26100.4270 (fixed in 10.0.26100.4270)
Published 2025-06-10. Last modified 2026-06-17.