Windows Server 2025
by Microsoft
CVEs (1,879)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20823 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62468 | Med | 0.36 | 5.5 | 0.01 | Dec 9, 2025 | Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62209 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62208 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. | ||
| CVE-2025-60706 | Med | 0.36 | 5.5 | 0.00 | Nov 11, 2025 | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59513 | Med | 0.36 | 5.5 | 0.00 | Nov 11, 2025 | Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59510 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. | ||
| CVE-2025-59509 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59260 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59253 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. | ||
| CVE-2025-59211 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59209 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59204 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59203 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59197 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59190 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. | ||
| CVE-2025-59188 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59186 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59184 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55699 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. |
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Page 69 of 94