VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2025-55694HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55692HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55680HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55677HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55339HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55328HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53768HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Xbox allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53150HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50175HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50152HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24052HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…

  • CVE-2025-55317HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55316HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55245HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55228HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

  • CVE-2025-55224HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

  • CVE-2025-54916HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

  • CVE-2025-54913HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54912HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54908HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-54907HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

  • CVE-2025-54906HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-54904HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54903HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54902HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54900HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54899HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54898HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54896HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54895HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54894HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

  • CVE-2025-54111HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54102HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54098HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54092HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54091HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53801HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53800HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49692HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55230HigAug 21, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53789HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53773HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2025-53761HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-53759HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-53741HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-53739HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-53738HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-53737HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-53735HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-53734HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

Page 71 of 314