6.5
CVE-2025-59214 - Microsoft Windows File Explorer Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
8.4
CVE-2025-59213 - Configuration Manager Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges locally.
7.4
CVE-2025-59210 - Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
5.5
CVE-2025-59209 - Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
7.1
CVE-2025-59208 - Windows MapUrlToZone Information Disclosure Vulnerability
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
7
CVE-2025-59205 - Windows Graphics Component Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
5.5
CVE-2025-59203 - Windows State Repository API Server File Information Disclosure Vulnerability
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
5
CVE-2025-59198 - Windows Search Service Denial of Service Vulnerability
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
5.5
CVE-2025-59197 - Windows ETL Channel Information Disclosure Vulnerability
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
7
CVE-2025-59194 - Windows Kernel Elevation of Privilege Vulnerability
Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.