7.5
CVE-2025-27484 - Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
7.5
CVE-2025-27485 - Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
7.5
CVE-2025-27469 - Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
7.8
CVE-2025-27467 - Windows Digital Media Elevation of Privilege Vulnerability
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-26679 - RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
8.4
CVE-2025-26678 - Windows Defender Application Control Security Feature Bypass Vulnerability
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
6.5
CVE-2025-26676 - Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
7.8
CVE-2025-26675 - Windows Subsystem for Linux Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
7.5
CVE-2025-26673 - Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
6.5
CVE-2025-26672 - Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.