5.9
CVE-2025-48823 - Windows Cryptographic Services Information Disclosure Vulnerability
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
8.6
CVE-2025-48822 - Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
7.1
CVE-2025-48821 - Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
7.8
CVE-2025-48820 - Windows AppX Deployment Service Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
7.1
CVE-2025-48819 - Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
6.8
CVE-2025-48818 - Windows BitLocker Security Feature Bypass Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
8.8
CVE-2025-48817 - Remote Desktop Client Remote Code Execution Vulnerability
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
7.8
CVE-2025-48816 - HID Class Driver Elevation of Privilege Vulnerability
Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-48815 - Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
7.5
CVE-2025-48814 - Remote Desktop Licensing Service Security Feature Bypass Vulnerability
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.