7
CVE-2025-59497 - Microsoft Defender for Linux Denial of Service Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.
7
CVE-2025-59289 - Windows Bluetooth Service Elevation of Privilege Vulnerability
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
9.8
CVE-2025-59287 - Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
7
CVE-2025-59285 - Azure Monitor Agent Elevation of Privilege Vulnerability
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-59278 - Windows Authentication Elevation of Privilege Vulnerability
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-59275 - Windows Authentication Elevation of Privilege Vulnerability
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
4.9
CVE-2025-37144 - Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOโฆ
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
7
CVE-2025-59261 - Windows Graphics Component Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
5.5
CVE-2025-59260 - Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
5.5
CVE-2025-59253 - Windows Search Service Denial of Service Vulnerability
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.