VYPR

Windows Server 2025

by Microsoft

CVEs (1,879)

  • CVE-2025-55684HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55681HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.05

    Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55678HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55340HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

  • CVE-2025-55331HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50174HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59220HigSep 18, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59216HigSep 18, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59215HigSep 18, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55223HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54115HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54114HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54112HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54108HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54105HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54099HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54093HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53807HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53802HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49734HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

Page 52 of 94