Windows Server 2025
by Microsoft
CVEs (1,879)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62757 | Med | 0.34 | 5.3 | 0.00 | Aug 11, 2026 | Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-45655 | Med | 0.34 | 5.3 | 0.00 | Jun 9, 2026 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2026-42914 | Med | 0.34 | 5.3 | 0.01 | Jun 9, 2026 | Windows Kerberos Denial of Service Vulnerability | ||
| CVE-2025-55229 | Med | 0.34 | 5.3 | 0.00 | Aug 21, 2025 | Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-61368 | Med | 0.33 | 5.0 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59198 | Med | 0.33 | 5.0 | 0.00 | Oct 14, 2025 | Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. | ||
| CVE-2025-55679 | Med | 0.33 | 5.1 | 0.00 | Oct 14, 2025 | Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-33069 | Med | 0.33 | 5.1 | 0.00 | Jun 10, 2025 | Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-26644 | Med | 0.33 | 5.1 | 0.01 | Apr 8, 2025 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2022-40733 | Med | 0.33 | 5.0 | 0.01 | Dec 18, 2024 | An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls… | ||
| CVE-2026-33829 | Med | 0.31 | 4.3 | 0.03 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-58719 | Med | 0.31 | 4.7 | 0.00 | Oct 14, 2025 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21179 | Med | 0.31 | 4.8 | 0.01 | Feb 11, 2025 | DHCP Client Service Denial of Service Vulnerability | ||
| CVE-2026-61350 | Med | 0.30 | 4.6 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2026-26175 | Med | 0.30 | 4.6 | 0.00 | Apr 14, 2026 | Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2026-20928 | Med | 0.30 | 4.6 | 0.00 | Apr 14, 2026 | Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2026-20834 | Med | 0.30 | 4.6 | 0.01 | Jan 13, 2026 | Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | ||
| CVE-2026-20828 | Med | 0.30 | 4.6 | 0.01 | Jan 13, 2026 | Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2025-21215 | Med | 0.30 | 4.6 | 0.01 | Jan 14, 2025 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2025-21213 | Med | 0.30 | 4.6 | 0.01 | Jan 14, 2025 | Secure Boot Security Feature Bypass Vulnerability |
- risk 0.34cvss 5.3epss 0.00
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.34cvss 5.3epss 0.00
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.34cvss 5.3epss 0.01
Windows Kerberos Denial of Service Vulnerability
- risk 0.34cvss 5.3epss 0.00
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
- risk 0.33cvss 5.0epss 0.00
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.33cvss 5.0epss 0.00
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
- risk 0.33cvss 5.1epss 0.00
Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.
- risk 0.33cvss 5.1epss 0.00
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
- risk 0.33cvss 5.1epss 0.01
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
- risk 0.33cvss 5.0epss 0.01
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafted set of syscalls…
- risk 0.31cvss 4.3epss 0.03
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.00
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.31cvss 4.8epss 0.01
DHCP Client Service Denial of Service Vulnerability
- risk 0.30cvss 4.6epss 0.00
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.30cvss 4.6epss 0.00
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.30cvss 4.6epss 0.00
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.30cvss 4.6epss 0.01
Secure Boot Security Feature Bypass Vulnerability
Page 73 of 94