NONE · 0

CVE-2025-7676

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. ...

Vulnerability Description

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. Vulnerable versions of Windows 11 for ARM attempt to load Base DLLs that would ordinarily not be loaded from the application directory. Fixed in release 24H2, but present in all earlier versions of Windows 11 for ARM CPUs.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-7676?

CVE-2025-7676 is a documented vulnerability. DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can plant a DLL in the same directory as the executable. ...

How severe is CVE-2025-7676?

CVSS scoring is not yet available for CVE-2025-7676. Check NVD for updates.

Is there a patch for CVE-2025-7676?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.