Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-49727 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49699 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-49685 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49678 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-48821 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-48819 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-47975 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-7326 | Hig | 0.46 | 7.0 | 0.01 | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon… | ||
| CVE-2025-30378 | Hig | 0.46 | 7.0 | 0.01 | May 13, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-29973 | Hig | 0.46 | 7.0 | 0.00 | May 13, 2025 | Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-29841 | Hig | 0.46 | 7.0 | 0.00 | May 13, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27468 | Hig | 0.46 | 7.0 | 0.00 | May 13, 2025 | Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21264 | Hig | 0.46 | 7.1 | 0.01 | May 13, 2025 | Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-29809 | Hig | 0.46 | 7.1 | 0.04 | Apr 8, 2025 | Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-27732 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27492 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27491 | Hig | 0.46 | 7.1 | 0.01 | Apr 8, 2025 | Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. | ||
| CVE-2025-27478 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27475 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26665 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26649 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26640 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21191 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26627 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-25008 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2025 | Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24078 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-24070 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-24036 | Hig | 0.46 | 7.0 | 0.00 | Feb 11, 2025 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | ||
| CVE-2025-21419 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2025 | Windows Setup Files Cleanup Elevation of Privilege Vulnerability | ||
| CVE-2025-21414 | Hig | 0.46 | 7.0 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2025-21379 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2025 | DHCP Client Service Remote Code Execution Vulnerability | ||
| CVE-2025-21194 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2025 | Microsoft Surface Security Feature Bypass Vulnerability | ||
| CVE-2025-21184 | Hig | 0.46 | 7.0 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2025-21346 | Hig | 0.46 | 7.1 | 0.01 | Jan 14, 2025 | Microsoft Office Security Feature Bypass Vulnerability | ||
| CVE-2025-21299 | Hig | 0.46 | 7.1 | 0.02 | Jan 14, 2025 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2024-43106 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and… | ||
| CVE-2024-42220 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this… | ||
| CVE-2024-42004 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program… | ||
| CVE-2024-41165 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and… | ||
| CVE-2024-41159 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability… | ||
| CVE-2024-41145 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a… | ||
| CVE-2024-41138 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious… | ||
| CVE-2024-39804 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this… | ||
| CVE-2024-49097 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2024-49095 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2024-49084 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-49059 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2024-49049 | Hig | 0.46 | 7.1 | 0.00 | Nov 12, 2024 | Visual Studio Code Remote Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-49048 | Hig | 0.46 | 8.1 | 0.01 | Nov 12, 2024 | TorchGeo Remote Code Execution Vulnerability | ||
| CVE-2024-43615 | Hig | 0.46 | 7.1 | 0.01 | Oct 8, 2024 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.00
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
- risk 0.46cvss 7.1epss 0.00
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
- risk 0.46cvss 7.0epss 0.00
Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon…
- risk 0.46cvss 7.0epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.00
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- risk 0.46cvss 7.1epss 0.04
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.0epss 0.01
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- risk 0.46cvss 7.0epss 0.00
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.46cvss 7.1epss 0.01
DHCP Client Service Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Surface Security Feature Bypass Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Office Security Feature Bypass Vulnerability
- risk 0.46cvss 7.1epss 0.02
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…
- risk 0.46cvss 7.0epss 0.00
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.00
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
- risk 0.46cvss 8.1epss 0.01
TorchGeo Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
Page 145 of 314