CVE-2026-27925: Windows UPnP Device Host Information Disclosure Vulnerability
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
Other sources
Windows UPnP Device Host Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6936Patch KB5082052 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7184Patch KB5082200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32690Patch KB5082063 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7184Patch KB5082200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5020Patch KB5082142 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1836Patch KB5083768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8644Patch KB5082123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26026Patch KB5082127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23132Patch KB5082126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9060Patch KB5082198 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2274Patch KB5082060 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8246Patch KB5083769
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27925?
CVE-2026-27925 has been assigned a medium severity rating due to its potential for information disclosure.
How do I fix CVE-2026-27925?
To fix CVE-2026-27925, apply the latest security patches provided by Microsoft for your affected Windows version.
What versions of Windows are affected by CVE-2026-27925?
CVE-2026-27925 affects multiple versions including Windows 10 (22H2, 21H2, 1809, 1607), Windows 11 (25H2, 23H2, 24H2), and various Windows Server editions.
What type of vulnerability is CVE-2026-27925?
CVE-2026-27925 is a use-after-free vulnerability within the Windows Universal Plug and Play (UPnP) Device Host.
Can CVE-2026-27925 be exploited remotely?
Yes, CVE-2026-27925 can potentially be exploited by an unauthorized attacker over an adjacent network.