Windows Server 2025
by Microsoft
CVEs (1,879)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49087 | Med | 0.30 | 4.6 | 0.01 | Dec 12, 2024 | Windows Mobile Broadband Driver Information Disclosure Vulnerability | ||
| CVE-2026-32209 | Med | 0.29 | 4.4 | 0.00 | May 12, 2026 | Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-32220 | Med | 0.29 | 4.4 | 0.00 | Apr 14, 2026 | Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-20962 | Med | 0.29 | 4.4 | 0.00 | Jan 13, 2026 | Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20825 | Med | 0.29 | 4.4 | 0.01 | Jan 13, 2026 | Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-47969 | Med | 0.29 | 4.4 | 0.01 | Jun 10, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24997 | Med | 0.29 | 4.4 | 0.01 | Mar 11, 2025 | Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | ||
| CVE-2026-20936 | Med | 0.28 | 4.3 | 0.00 | Jan 13, 2026 | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | ||
| CVE-2025-54917 | Med | 0.28 | 4.3 | 0.01 | Sep 9, 2025 | Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-54107 | Med | 0.28 | 4.3 | 0.01 | Sep 9, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-24055 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2025 | Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | ||
| CVE-2025-21247 | Med | 0.28 | 4.3 | 0.03 | Mar 11, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-21332 | Med | 0.28 | 4.3 | 0.01 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21329 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21328 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21269 | Med | 0.28 | 4.3 | 0.05 | Jan 14, 2025 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2025-21268 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21219 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21189 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2024-49103 | Med | 0.28 | 4.3 | 0.01 | Dec 12, 2024 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
- risk 0.30cvss 4.6epss 0.01
Windows Mobile Broadband Driver Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.00
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.00
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.00
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
- risk 0.28cvss 4.3epss 0.01
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
- risk 0.28cvss 4.3epss 0.03
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.05
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.01
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
Page 74 of 94