Windows Server 2025
by Microsoft
CVEs (1,909)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-30400 | Hig | 0.63 | 7.8 | 0.02 | KEV | May 13, 2025 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-24993 | Hig | 0.63 | 7.8 | 0.02 | KEV | Mar 11, 2025 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
| CVE-2025-24985 | Hig | 0.63 | 7.8 | 0.04 | KEV | Mar 11, 2025 | Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. | |
| CVE-2025-21418 | Hig | 0.63 | 7.8 | 0.02 | KEV | Feb 11, 2025 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
| CVE-2025-21335 | Hig | 0.63 | 7.8 | 0.01 | KEV | Jan 14, 2025 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| CVE-2025-21334 | Hig | 0.63 | 7.8 | 0.02 | KEV | Jan 14, 2025 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| CVE-2026-42904 | Cri | 0.62 | 9.6 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-24054 | Med | 0.62 | 6.5 | 0.59 | KEV | Mar 11, 2025 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2025-21293 | Hig | 0.62 | 8.8 | 0.19 | Jan 14, 2025 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2025-62215 | Hig | 0.61 | 7.0 | 0.06 | KEV | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
| CVE-2024-43451 | Med | 0.61 | 6.5 | 0.82 | KEV | Nov 12, 2024 | NTLM Hash Disclosure Spoofing Vulnerability | |
| CVE-2025-53778 | Hig | 0.60 | 8.8 | 0.38 | Aug 12, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-45602 | Cri | 0.59 | 9.1 | 0.00 | Jun 9, 2026 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2025-55234 | Hig | 0.59 | 8.8 | 0.20 | Sep 9, 2025 | SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for… | ||
| CVE-2025-54918 | Hig | 0.59 | 8.8 | 0.19 | Sep 9, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-50171 | Cri | 0.59 | 9.1 | 0.01 | Aug 12, 2025 | Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-68820 | Hig | 0.58 | 7.0 | 0.00 | KEV | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-54110 | Hig | 0.58 | 8.8 | 0.04 | Sep 9, 2025 | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53145 | Hig | 0.58 | 8.8 | 0.06 | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||
| CVE-2025-53144 | Hig | 0.58 | 8.8 | 0.06 | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. |
- risk 0.63cvss 7.8epss 0.02
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- risk 0.63cvss 7.8epss 0.02
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- risk 0.63cvss 7.8epss 0.04
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
- risk 0.63cvss 7.8epss 0.02
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.63cvss 7.8epss 0.01
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- risk 0.63cvss 7.8epss 0.02
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- risk 0.62cvss 9.6epss 0.00
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.62cvss 6.5epss 0.59
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.62cvss 8.8epss 0.19
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.61cvss 7.0epss 0.06
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.61cvss 6.5epss 0.82
NTLM Hash Disclosure Spoofing Vulnerability
- risk 0.60cvss 8.8epss 0.38
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.00
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
- risk 0.59cvss 8.8epss 0.20
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for…
- risk 0.59cvss 8.8epss 0.19
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.01
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.58cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.58cvss 8.8epss 0.04
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.58cvss 8.8epss 0.06
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
- risk 0.58cvss 8.8epss 0.06
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
Page 3 of 96