Windows Server 2025
by Microsoft
CVEs (1,899)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32091 | Hig | 0.55 | 8.4 | 0.00 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-33067 | Hig | 0.55 | 8.4 | 0.00 | Jun 10, 2025 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-26678 | Hig | 0.55 | 8.4 | 0.01 | Apr 8, 2025 | Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-24084 | Hig | 0.55 | 8.4 | 0.01 | Mar 11, 2025 | Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-49113 | Hig | 0.55 | 7.5 | 0.83 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | ||
| CVE-2024-49105 | Hig | 0.55 | 8.4 | 0.02 | Dec 12, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2026-56179 | Hig | 0.54 | 8.3 | 0.00 | Aug 11, 2026 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | ||
| CVE-2026-21250 | Hig | 0.54 | 7.8 | 0.01 | Feb 10, 2026 | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59254 | Hig | 0.54 | 7.8 | 0.01 | Oct 14, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49730 | Hig | 0.54 | 7.8 | 0.01 | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49683 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-47987 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-33071 | Hig | 0.54 | 8.1 | 0.17 | Jun 10, 2025 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21309 | Hig | 0.54 | 8.1 | 0.15 | Jan 14, 2025 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49122 | Hig | 0.54 | 8.1 | 0.20 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-43642 | Hig | 0.54 | 7.5 | 0.62 | Nov 12, 2024 | Windows SMB Denial of Service Vulnerability | ||
| CVE-2026-66802 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65796 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65679 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62889 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
- risk 0.55cvss 8.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.00
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- risk 0.55cvss 8.4epss 0.01
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
- risk 0.55cvss 8.4epss 0.01
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 7.5epss 0.83
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- risk 0.55cvss 8.4epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.54cvss 8.3epss 0.00
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
- risk 0.54cvss 7.8epss 0.01
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.01
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.01
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.02
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 8.1epss 0.17
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
- risk 0.54cvss 8.1epss 0.15
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.54cvss 8.1epss 0.20
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.54cvss 7.5epss 0.62
Windows SMB Denial of Service Vulnerability
- risk 0.53cvss 8.1epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Page 11 of 95