Windows Server 2025
by Microsoft
CVEs (1,909)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-49724 | Hig | 0.58 | 8.8 | 0.08 | Jul 8, 2025 | Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-29962 | Hig | 0.58 | 8.8 | 0.14 | May 13, 2025 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21391 | Hig | 0.58 | 7.1 | 0.02 | KEV | Feb 11, 2025 | Windows Storage Elevation of Privilege Vulnerability | |
| CVE-2026-62823 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62822 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62818 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62817 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62816 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62800 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62795 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62790 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62785 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62784 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-49179 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-47653 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-47289 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-45648 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-42985 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-40403 | Hig | 0.57 | 8.8 | 0.00 | May 12, 2026 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | ||
| CVE-2026-34329 | Hig | 0.57 | 8.8 | 0.00 | May 12, 2026 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. |
- risk 0.58cvss 8.8epss 0.08
Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
- risk 0.58cvss 8.8epss 0.14
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
- risk 0.58cvss 7.1epss 0.02
Windows Storage Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
Page 4 of 96