Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55694 | Hig | 0.51 | 7.8 | 0.03 | Oct 14, 2025 | Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55692 | Hig | 0.51 | 7.8 | 0.03 | Oct 14, 2025 | Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55680 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55677 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55339 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55328 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53768 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Use after free in Xbox allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53150 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-50175 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-50152 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24052 | Hig | 0.51 | 7.8 | 0.02 | Oct 14, 2025 | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax… | ||
| CVE-2025-55317 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55316 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55245 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55228 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | ||
| CVE-2025-55224 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | ||
| CVE-2025-54916 | Hig | 0.51 | 7.8 | 0.02 | Sep 9, 2025 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | ||
| CVE-2025-54913 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54912 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54908 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54907 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54906 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54904 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54903 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54902 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54900 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54899 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54898 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54896 | Hig | 0.51 | 7.8 | 0.01 | Sep 9, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-54895 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54894 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | ||
| CVE-2025-54111 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54102 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54098 | Hig | 0.51 | 7.8 | 0.03 | Sep 9, 2025 | Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54092 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54091 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53801 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53800 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49692 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55230 | Hig | 0.51 | 7.8 | 0.00 | Aug 21, 2025 | Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53789 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53773 | Hig | 0.51 | 7.8 | 0.03 | Aug 12, 2025 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53761 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53759 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53741 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53739 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53738 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53737 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53735 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53734 | Hig | 0.51 | 7.8 | 0.00 | Aug 12, 2025 | Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. |
- risk 0.51cvss 7.8epss 0.03
Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.02
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…
- risk 0.51cvss 7.8epss 0.00
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.02
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
Page 71 of 314