7.8
CVE-2025-49694 - Microsoft Brokering File System Elevation of Privilege Vulnerability
Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
8
CVE-2025-49691 - Windows Miracast Wireless Display Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
7.4
CVE-2025-49690 - Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
7.8
CVE-2025-49689 - Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
8.8
CVE-2025-49688 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
8.8
CVE-2025-49687 - Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-49686 - Windows TCP/IP Driver Elevation of Privilege Vulnerability
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
7
CVE-2025-49677 - Microsoft Brokering File System Elevation of Privilege Vulnerability
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
8.8
CVE-2025-49676 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
8.8
CVE-2025-49674 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.