7.8
CVE-2025-59517 - Windows Storage VSP Driver Elevation of Privilege Vulnerability
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-59516 - Windows Storage VSP Driver Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-64673 - Windows Storage VSP Driver Elevation of Privilege Vulnerability
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
6.5
CVE-2025-64670 - Windows DirectX Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
7.5
CVE-2025-64666 - Microsoft Exchange Server Elevation of Privilege Vulnerability
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
5.3
CVE-2025-64667 - Microsoft Exchange Server Spoofing Vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
7.5
CVE-2025-64658 - Windows File Explorer Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
7
CVE-2025-62573 - DirectX Graphics Kernel Elevation of Privilege Vulnerability
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-62572 - Application Information Service Elevation of Privilege Vulnerability
Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-62571 - Windows Installer Elevation of Privilege Vulnerability
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.