7.8
CVE-2025-60714 - Windows OLE Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
7.8
CVE-2025-60713 - Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
7
CVE-2025-59515 - Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-59514 - Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
6.7
CVE-2025-47179 - Configuration Manager Elevation of Privilege Vulnerability
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
5.5
CVE-2025-59240 - Microsoft Excel Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
8
CVE-2025-62452 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
8.8
CVE-2025-62220 - Windows Subsystem for Linux GUI Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.
7
CVE-2025-62219 - Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
7
CVE-2025-62218 - Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.