VYPR

Windows Server 2025

by Microsoft

CVEs (1,879)

  • CVE-2025-55697HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55696HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55694HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55692HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55680HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55677HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55339HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55328HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53150HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50175HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50152HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24052HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…

  • CVE-2025-55228HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

  • CVE-2025-55224HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

  • CVE-2025-54916HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

  • CVE-2025-54913HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54912HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54895HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54894HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

  • CVE-2025-54111HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

Page 30 of 94