3.3
CVE-2025-59284 - Windows NTLM Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
7
CVE-2025-59282 - Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulneraβ¦
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.8
CVE-2025-59281 - Xbox Gaming Services Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
5.5
CVE-2025-47979 - Microsoft Failover Cluster Information Disclosure Vulnerability
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
3.1
CVE-2025-59280 - Windows SMB Client Tampering Vulnerability
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
7.8
CVE-2025-59277 - Windows Authentication Elevation of Privilege Vulnerability
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
6.5
CVE-2025-59259 - Windows Local Session Manager (LSM) Denial of Service Vulnerability
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
6.2
CVE-2025-59258 - Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
6.5
CVE-2025-59257 - Windows Local Session Manager (LSM) Denial of Service Vulnerability
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
7.8
CVE-2025-59255 - Windows DWM Core Library Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.