6.5
CVE-2025-47997 - Microsoft SQL Server Information Disclosure Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
7.8
CVE-2025-49692 - Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-55317 - Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-55316 - Azure Connected Machine Agent Elevation of Privilege Vulnerability
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
7.5
CVE-2025-55243 - Microsoft OfficePlus Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.
7.8
CVE-2025-55245 - Xbox Gaming Services Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.
7.3
CVE-2025-55236 - Graphics Kernel Remote Code Execution Vulnerability
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.
9.8
CVE-2025-55232 - Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.
7.8
CVE-2025-55228 - Windows Graphics Component Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
6.7
CVE-2025-55226 - Graphics Kernel Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.