Windows Server 2025
by Microsoft
CVEs (1,879)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-29835 | Med | 0.42 | 6.5 | 0.01 | May 13, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29832 | Med | 0.42 | 6.5 | 0.01 | May 13, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29830 | Med | 0.42 | 6.5 | 0.01 | May 13, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-27738 | Med | 0.42 | 6.5 | 0.03 | Apr 8, 2025 | Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-27474 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-26676 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-26672 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-26667 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-26664 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-26651 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | ||
| CVE-2025-21203 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-21197 | Med | 0.42 | 6.5 | 0.03 | Apr 8, 2025 | Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | ||
| CVE-2025-24996 | Med | 0.42 | 6.5 | 0.01 | Mar 11, 2025 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-24984 | Med | 0.42 | 4.6 | 0.02 | KEV | Mar 11, 2025 | Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | |
| CVE-2025-21352 | Med | 0.42 | 6.5 | 0.01 | Feb 11, 2025 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | ||
| CVE-2025-21254 | Med | 0.42 | 6.5 | 0.01 | Feb 11, 2025 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | ||
| CVE-2025-21216 | Med | 0.42 | 6.5 | 0.01 | Feb 11, 2025 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | ||
| CVE-2025-21212 | Med | 0.42 | 6.5 | 0.01 | Feb 11, 2025 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | ||
| CVE-2025-21314 | Med | 0.42 | 6.5 | 0.01 | Jan 14, 2025 | Windows SmartScreen Spoofing Vulnerability | ||
| CVE-2025-21313 | Med | 0.42 | 6.5 | 0.02 | Jan 14, 2025 | Windows Security Account Manager (SAM) Denial of Service Vulnerability |
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.03
Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.03
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
- risk 0.42cvss 6.5epss 0.01
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 4.6epss 0.02
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.42cvss 6.5epss 0.01
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows SmartScreen Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Security Account Manager (SAM) Denial of Service Vulnerability
Page 62 of 94