Filtered by vendor Microsoft Subscriptions
Filtered by product Windows Server Subscriptions
Total 527 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-54099 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-02 7 High
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-54098 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-02 7.8 High
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-54097 1 Microsoft 9 Windows, Windows Server, Windows Server 2008 and 6 more 2025-10-02 6.5 Medium
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-54107 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-02 4.3 Medium
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-55228 1 Microsoft 12 Windows, Windows 10, Windows 10 21h2 and 9 more 2025-10-02 7.8 High
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
CVE-2025-54918 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-02 8.8 High
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-54917 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-02 4.3 Medium
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-54912 1 Microsoft 20 Bitlocker, Windows, Windows 10 and 17 more 2025-10-02 7.8 High
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
CVE-2025-59215 1 Microsoft 6 Graphics Component, Windows, Windows 11 and 3 more 2025-09-30 7 High
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-59220 1 Microsoft 13 Windows, Windows 10, Windows 10 21h2 and 10 more 2025-09-26 7 High
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59216 1 Microsoft 5 Windows, Windows 11, Windows 11 24h2 and 2 more 2025-09-26 7 High
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-55224 1 Microsoft 15 Hyper-v, Windows, Windows 10 and 12 more 2025-09-26 7.8 High
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
CVE-2025-54911 1 Microsoft 20 Bitlocker, Windows, Windows 10 and 17 more 2025-09-26 7.3 High
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
CVE-2025-53809 1 Microsoft 5 Windows, Windows 11, Windows 11 24h2 and 2 more 2025-09-26 6.5 Medium
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
CVE-2022-40733 1 Microsoft 4 Windows, Windows 11 21h2, Windows Server and 1 more 2025-08-26 5 Medium
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls can lead to a reboot. An unprivileged user can run specially-crafted code to trigger Denial Of Service.
CVE-2025-49666 1 Microsoft 6 Windows Server, Windows Server 2016, Windows Server 2019 and 3 more 2025-08-23 7.2 High
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
CVE-2025-49735 1 Microsoft 9 Server, Windows, Windows Server and 6 more 2025-08-23 8.1 High
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2022-29126 1 Microsoft 9 Windows 10, Windows 11, Windows 8.1 and 6 more 2025-07-24 7 High
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
CVE-2025-33050 1 Microsoft 6 Windows Server, Windows Server 2016, Windows Server 2019 and 3 more 2025-07-11 7.5 High
Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-32725 1 Microsoft 6 Windows Server, Windows Server 2016, Windows Server 2019 and 3 more 2025-07-11 7.5 High
Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.