CVE-2025-26665 | Microsoft Windows up to Server 2025 upnphost.dll sensitive data storage in improperly locked memory
A vulnerability classified as critical was found in Microsoft Windows. This vulnerability affects unknown code in the library upnphost.dll. The manipulation leads to sensitive data storage in improperly locked memory.
This vulnerability was named CVE-2025-26665. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.