VYPR

Windows Server 2025

by Microsoft

CVEs (1,879)

  • CVE-2026-0386HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-64658HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60704HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-59502HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

  • CVE-2025-58726HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-55326HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-54919HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

  • CVE-2025-53805HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

  • CVE-2025-55231HigAug 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50169HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.

  • CVE-2025-49744HigJul 8, 2025
    risk 0.49cvss 7.0epss 0.01

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48814HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-33068HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • CVE-2025-33056HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

  • CVE-2025-33050HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

  • CVE-2025-32725HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

  • CVE-2025-32724HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2025-29969HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.

  • CVE-2025-29842HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-29831HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Page 40 of 94