7.8
CVE-2025-49679 - Windows Shell Elevation of Privilege Vulnerability
Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.
7
CVE-2025-49678 - NTFS Elevation of Privilege Vulnerability
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-49675 - Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
8.8
CVE-2025-49673 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
8.8
CVE-2025-49669 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
8.8
CVE-2025-49668 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
7.8
CVE-2025-49667 - Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
7.2
CVE-2025-49666 - Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
7.8
CVE-2025-49665 - Workspace Broker Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.
5.5
CVE-2025-49664 - Windows User-Mode Driver Framework Host Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally.