Windows 11 25h2
by Microsoft
CVEs (597)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55330 | 0.00 | — | 0.01 | Oct 14, 2025 | Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | |||
| CVE-2025-55328 | 0.00 | — | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-53768 | 0.00 | — | 0.00 | Oct 14, 2025 | Use after free in Xbox allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-53139 | 0.00 | — | 0.00 | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. | |||
| CVE-2025-50175 | 0.00 | — | 0.00 | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-53150 | 0.00 | — | 0.00 | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-50152 | 0.00 | — | 0.00 | Oct 14, 2025 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-53717 | 0.00 | — | 0.00 | Oct 14, 2025 | Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-25004 | 0.00 | — | 0.00 | Oct 14, 2025 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-48813 | 0.00 | — | 0.00 | Oct 14, 2025 | Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. | |||
| CVE-2025-59295 | 0.00 | — | 0.02 | Oct 14, 2025 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | |||
| CVE-2025-59294 | 0.00 | — | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | |||
| CVE-2025-59284 | 0.00 | — | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | |||
| CVE-2025-59282 | 0.00 | — | 0.01 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-59259 | 0.00 | — | 0.01 | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | |||
| CVE-2025-59257 | 0.00 | — | 0.01 | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | |||
| CVE-2025-59255 | 0.00 | — | 0.00 | Oct 14, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-49708 | 0.00 | — | 0.01 | Oct 14, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. | |||
| CVE-2025-59242 | 0.00 | — | 0.00 | Oct 14, 2025 | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |||
| CVE-2025-59211 | 0.00 | — | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. |
- CVE-2025-55330Oct 14, 2025risk 0.00cvss —epss 0.01
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-55328Oct 14, 2025risk 0.00cvss —epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-53768Oct 14, 2025risk 0.00cvss —epss 0.00
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
- CVE-2025-53139Oct 14, 2025risk 0.00cvss —epss 0.00
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
- CVE-2025-50175Oct 14, 2025risk 0.00cvss —epss 0.00
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- CVE-2025-53150Oct 14, 2025risk 0.00cvss —epss 0.00
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- CVE-2025-50152Oct 14, 2025risk 0.00cvss —epss 0.00
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-53717Oct 14, 2025risk 0.00cvss —epss 0.00
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- CVE-2025-25004Oct 14, 2025risk 0.00cvss —epss 0.00
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
- CVE-2025-48813Oct 14, 2025risk 0.00cvss —epss 0.00
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
- CVE-2025-59295Oct 14, 2025risk 0.00cvss —epss 0.02
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
- CVE-2025-59294Oct 14, 2025risk 0.00cvss —epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
- CVE-2025-59284Oct 14, 2025risk 0.00cvss —epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
- CVE-2025-59282Oct 14, 2025risk 0.00cvss —epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- CVE-2025-59259Oct 14, 2025risk 0.00cvss —epss 0.01
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- CVE-2025-59257Oct 14, 2025risk 0.00cvss —epss 0.01
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
- CVE-2025-59255Oct 14, 2025risk 0.00cvss —epss 0.00
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- CVE-2025-49708Oct 14, 2025risk 0.00cvss —epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
- CVE-2025-59242Oct 14, 2025risk 0.00cvss —epss 0.00
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-59211Oct 14, 2025risk 0.00cvss —epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
Page 28 of 30