VYPR

Windows 11 25h2

by Microsoft

CVEs (1,162)

  • CVE-2025-60717HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60716HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59515HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59508HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59507HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59506HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59282HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-59261HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59208HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.00

    Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59205HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59202HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59196HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59195HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.

  • CVE-2025-59194HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.03

    Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59193HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58738HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58736HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58735HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58734HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58733HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Page 29 of 59