Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-59277 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55701 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55696 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55677 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24052 | Hig | 0.51 | 7.8 | 0.02 | Oct 14, 2025 | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax… | ||
| CVE-2025-54895 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49733 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-47962 | Hig | 0.51 | 7.8 | 0.01 | Jun 10, 2025 | Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24074 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24044 | Hig | 0.51 | 7.8 | 0.01 | Mar 11, 2025 | Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21325 | Hig | 0.51 | 7.8 | 0.00 | Jan 17, 2025 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | ||
| CVE-2025-21378 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Windows CSC Service Elevation of Privilege Vulnerability | ||
| CVE-2024-43644 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Windows Client-Side Caching Elevation of Privilege Vulnerability | ||
| CVE-2024-43641 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Windows Registry Elevation of Privilege Vulnerability | ||
| CVE-2024-43452 | Hig | 0.51 | 7.5 | 0.28 | Nov 12, 2024 | Windows Registry Elevation of Privilege Vulnerability | ||
| CVE-2024-43551 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Storage Elevation of Privilege Vulnerability | ||
| CVE-2024-43528 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | ||
| CVE-2024-43516 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | ||
| CVE-2024-30073 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | Windows Security Zone Mapping Security Feature Bypass Vulnerability | ||
| CVE-2024-38142 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.00
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows CSC Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Client-Side Caching Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Registry Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.28
Windows Registry Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Storage Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Security Zone Mapping Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Page 26 of 133