6.5
CVE-2025-47978 - Windows Kerberos Denial of Service Vulnerability
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
7
CVE-2025-47975 - Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-47973 - Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
3.5
CVE-2025-49760 - Windows Storage Spoofing Vulnerability
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
3.3
CVE-2025-49756 - Office Developer Platform Security Feature Bypass Vulnerability
Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
8.8
CVE-2025-49753 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
8
CVE-2025-47178 - Microsoft Configuration Manager Remote Code Execution Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.
8.1
CVE-2025-49735 - Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
3.1
CVE-2025-49731 - Microsoft Teams Elevation of Privilege Vulnerability
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
7.8
CVE-2025-49726 - Windows Notification Elevation of Privilege Vulnerability
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.