VYPR

Windows 11 25h2

by Microsoft

Source repositories

CVEs (1,186)

  • CVE-2025-58722HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58720HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

  • CVE-2025-58714HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55701HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55696HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55694HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55692HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55680HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55677HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55339HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55328HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53768HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Xbox allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53150HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50175HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50152HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24052HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…

  • CVE-2026-20852HigJan 13, 2026
    risk 0.50cvss 7.7epss 0.01

    Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

  • CVE-2026-20804HigJan 13, 2026
    risk 0.50cvss 7.7epss 0.01

    Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

  • CVE-2025-59200HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.

  • CVE-2025-55698HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.01

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

Page 20 of 60