threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft windows server 2019
Product
microsoft windows server 2019
500 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-42825
< 10.0.17763.8755
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-41097
< 10.0.17763.8755
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature l
6.7
MEDIUM
CVE-2026-41095
< 10.0.17763.8755
Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-41089
< 10.0.17763.8755
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2026-40415
< 10.0.17763.8755
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
8.1
HIGH
CVE-2026-40414
< 10.0.17763.8755
Windows TCP/IP Denial of Service Vulnerability
7.4
HIGH
CVE-2026-40413
< 10.0.17763.8755
Windows TCP/IP Denial of Service Vulnerability
7.4
HIGH
CVE-2026-40410
< 10.0.17763.8755
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-40408
< 10.0.17763.8755
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-40407
< 10.0.17763.8755
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-40406
< 10.0.17763.8755
Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
7.5
HIGH
CVE-2026-40403
< 10.0.17763.8755
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
8.8
HIGH
CVE-2026-40401
< 10.0.17763.8755
Windows TCP/IP Denial of Service Vulnerability
7.1
HIGH
CVE-2026-40399
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized
7.8
HIGH
CVE-2026-40398
< 10.0.17763.8755
Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-40397
< 10.0.17763.8755
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-40382
< 10.0.17763.8755
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-40380
< 10.0.17763.8755
Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack
6.2
MEDIUM
CVE-2026-40377
< 10.0.17763.8755
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-35424
< 10.0.17763.8755
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker
7.5
HIGH
CVE-2026-35423
< 10.0.17763.8755
Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
5.4
MEDIUM
CVE-2026-35422
< 10.0.17763.8755
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feat
6.5
MEDIUM
CVE-2026-35421
< 10.0.17763.8755
Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2026-35420
< 10.0.17763.8755
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-35418
< 10.0.17763.8755
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-35417
< 10.0.17763.8755
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-35416
< 10.0.17763.8755
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorize
7.0
HIGH
CVE-2026-35415
< 10.0.17763.8755
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-34351
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized
7.8
HIGH
CVE-2026-34347
< 10.0.17763.8755
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-34345
< 10.0.17763.8755
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorize
7.0
HIGH
CVE-2026-34344
< 10.0.17763.8755
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorize
7.8
HIGH
CVE-2026-34343
< 10.0.17763.8755
Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges l
7.8
HIGH
CVE-2026-34342
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components al
7.0
HIGH
CVE-2026-34341
< 10.0.17763.8755
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-34340
< 10.0.17763.8755
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-34339
< 10.0.17763.8755
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service loc
5.5
MEDIUM
CVE-2026-34338
< 10.0.17763.8755
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-34337
< 10.0.17763.8755
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-34336
< 10.0.17763.8755
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-34334
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized
7.8
HIGH
CVE-2026-34333
< 10.0.17763.8755
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-34331
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.0
HIGH
CVE-2026-34330
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.8
HIGH
CVE-2026-34329
< 10.0.17763.8755
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
8.8
HIGH
CVE-2026-33839
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.0
HIGH
CVE-2026-33838
< 10.0.17763.8755
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-33837
< 10.0.17763.8755
Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-33835
< 10.0.17763.8755
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-33834
< 10.0.17763.8755
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32209
< 10.0.17763.8755
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
4.4
MEDIUM
CVE-2026-32170
< 10.0.17763.8755
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
6.7
MEDIUM
CVE-2026-32161
< 10.0.17763.8755
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver
7.5
HIGH
CVE-2026-21530
< 10.0.17763.8755
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
6.7
MEDIUM
CVE-2026-33829
< 10.0.17763.8644
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spo
4.3
MEDIUM
CVE-2026-33827
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthoriz
8.1
HIGH
CVE-2026-33826
< 10.0.17763.8644
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
8.0
HIGH
CVE-2026-33824
< 10.0.17763.8644
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2026-33104
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.0
HIGH
CVE-2026-33100
< 10.0.17763.8644
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-33099
< 10.0.17763.8644
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-33098
< 10.0.17763.8644
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32225
< 10.0.17763.8644
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
8.8
HIGH
CVE-2026-32217
< 10.0.17763.8644
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-32215
< 10.0.17763.8644
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-32214
< 10.0.17763.8644
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-32212
< 10.0.17763.8644
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker
5.5
MEDIUM
CVE-2026-32202
< 10.0.17763.8644
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
4.3
MEDIUM
CVE-2026-32183
< 10.0.17763.8644
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorize
7.8
HIGH
CVE-2026-32165
< 10.0.17763.8644
Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32164
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows
7.8
HIGH
CVE-2026-32163
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows
7.8
HIGH
CVE-2026-32162
< 10.0.17763.8644
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges loc
8.4
HIGH
CVE-2026-32160
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows a
7.8
HIGH
CVE-2026-32159
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows a
7.8
HIGH
CVE-2026-32158
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows a
7.8
HIGH
CVE-2026-32157
< 10.0.17763.8644
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2026-32156
< 10.0.17763.8644
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
7.4
HIGH
CVE-2026-32151
< 10.0.17763.8644
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information
6.5
MEDIUM
CVE-2026-32150
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.d
7.0
HIGH
CVE-2026-32149
< 10.0.17763.8644
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
7.3
HIGH
CVE-2026-32093
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.d
7.0
HIGH
CVE-2026-32091
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System all
8.4
HIGH
CVE-2026-32090
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows
7.8
HIGH
CVE-2026-32089
< 10.0.17763.8644
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32088
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an
6.1
MEDIUM
CVE-2026-32087
< 10.0.17763.8644
Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-32086
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.d
7.0
HIGH
CVE-2026-32085
< 10.0.17763.8644
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to discl
5.5
MEDIUM
CVE-2026-32084
< 10.0.17763.8644
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-32083
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an auth
7.0
HIGH
CVE-2026-32082
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an auth
7.0
HIGH
CVE-2026-32081
< 10.0.17763.8644
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-32080
< 10.0.17763.8644
Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-32079
< 10.0.17763.8644
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-32078
< 10.0.17763.8644
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32077
< 10.0.17763.8644
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privi
7.8
HIGH
CVE-2026-32075
< 10.0.17763.8644
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-32074
< 10.0.17763.8644
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32073
< 10.0.17763.8644
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-32072
< 10.0.17763.8644
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
6.2
MEDIUM
CVE-2026-32071
< 10.0.17763.8644
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny ser
7.5
HIGH
CVE-2026-32070
< 10.0.17763.8644
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-32069
< 10.0.17763.8644
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-32068
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an auth
7.0
HIGH
CVE-2026-27930
< 10.0.17763.8644
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-27929
< 10.0.17763.8644
Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-27928
< 10.0.17763.8644
Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.
8.7
HIGH
CVE-2026-27927
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allow
7.8
HIGH
CVE-2026-27926
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Dri
7.0
HIGH
CVE-2026-27925
< 10.0.17763.8644
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2026-27923
< 10.0.17763.8644
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-27922
< 10.0.17763.8644
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-27921
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized
7.0
HIGH
CVE-2026-27920
< 10.0.17763.8644
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privi
7.8
HIGH
CVE-2026-27919
< 10.0.17763.8644
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privi
7.8
HIGH
CVE-2026-27918
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized
7.8
HIGH
CVE-2026-27917
< 10.0.17763.8644
Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges loc
7.0
HIGH
CVE-2026-27916
< 10.0.17763.8644
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-27915
< 10.0.17763.8644
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-27914
< 10.0.17763.8644
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-27913
< 10.0.17763.8644
Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.
7.7
HIGH
CVE-2026-27912
< 10.0.17763.8644
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
8.0
HIGH
CVE-2026-27911
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows
7.8
HIGH
CVE-2026-27910
< 10.0.17763.8644
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2026-27909
< 10.0.17763.8644
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-27908
< 10.0.17763.8644
Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-26184
< 10.0.17763.8644
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26183
< 10.0.17763.8644
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26182
< 10.0.17763.8644
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-26180
< 10.0.17763.8644
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26178
< 10.0.17763.8644
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges lo
8.8
HIGH
CVE-2026-26177
< 10.0.17763.8644
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-26176
< 10.0.17763.8644
Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges loc
7.8
HIGH
CVE-2026-26175
< 10.0.17763.8644
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical
4.6
MEDIUM
CVE-2026-26174
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allow
7.0
HIGH
CVE-2026-26173
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver f
7.0
HIGH
CVE-2026-26170
< 10.0.17763.8644
Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26169
< 10.0.17763.8644
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
6.1
MEDIUM
CVE-2026-26168
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver f
7.8
HIGH
CVE-2026-26167
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows a
8.8
HIGH
CVE-2026-26163
< 10.0.17763.8644
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26162
< 10.0.17763.8644
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges l
7.8
HIGH
CVE-2026-26161
< 10.0.17763.8644
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26160
< 10.0.17763.8644
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate
7.8
HIGH
CVE-2026-26159
< 10.0.17763.8644
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate
7.8
HIGH
CVE-2026-26156
< 10.0.17763.8644
Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2026-26155
< 10.0.17763.8644
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2026-26154
< 10.0.17763.8644
Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
7.5
HIGH
CVE-2026-26153
< 10.0.17763.8644
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26152
< 10.0.17763.8644
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges lo
7.0
HIGH
CVE-2026-26151
< 10.0.17763.8644
Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over
7.1
HIGH
CVE-2026-23670
< 10.0.17763.8644
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a sec
5.7
MEDIUM
CVE-2026-20930
< 10.0.17763.8644
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20928
< 10.0.17763.8644
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized
4.6
MEDIUM
CVE-2026-20806
< 10.0.17763.8644
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2026-0390
< 10.0.17763.8644
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feat
6.7
MEDIUM
CVE-2026-26128
< 10.0.17763.8511
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-26111
< 10.0.17763.8511
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code o
8.0
HIGH
CVE-2026-25190
< 10.0.17763.8511
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2026-25189
< 10.0.17763.8511
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-25188
< 10.0.17763.8511
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent net
8.8
HIGH
CVE-2026-25187
< 10.0.17763.8511
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges loc
7.8
HIGH
CVE-2026-25186
< 10.0.17763.8511
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an author
5.5
MEDIUM
CVE-2026-25185
< 10.0.17763.8511
Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to per
5.3
MEDIUM
CVE-2026-25181
< 10.0.17763.8511
Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
7.5
HIGH
CVE-2026-25180
< 10.0.17763.8511
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-25179
< 10.0.17763.8511
Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to e
7.0
HIGH
CVE-2026-25178
< 10.0.17763.8511
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-25177
< 10.0.17763.8511
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to e
8.8
HIGH
CVE-2026-25176
< 10.0.17763.8511
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges local
7.8
HIGH
CVE-2026-25175
< 10.0.17763.8511
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-25174
< 10.0.17763.8511
Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-25173
< 10.0.17763.8511
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code o
8.0
HIGH
CVE-2026-25172
< 10.0.17763.8511
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code o
8.0
HIGH
CVE-2026-25171
< 10.0.17763.8511
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-25169
< 10.0.17763.8511
Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
6.2
MEDIUM
CVE-2026-25168
< 10.0.17763.8511
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
6.2
MEDIUM
CVE-2026-25166
< 10.0.17763.8511
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2026-25165
< 10.0.17763.8511
Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-24297
< 10.0.17763.8511
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthor
6.5
MEDIUM
CVE-2026-24296
< 10.0.17763.8511
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service
7.0
HIGH
CVE-2026-24295
< 10.0.17763.8511
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service
7.0
HIGH
CVE-2026-24294
< 10.0.17763.8511
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-24292
< 10.0.17763.8511
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-24291
< 10.0.17763.8511
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized
7.8
HIGH
CVE-2026-24290
< 10.0.17763.8511
Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-24289
< 10.0.17763.8511
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-24287
< 10.0.17763.8511
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-24285
< 10.0.17763.8511
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-23674
< 10.0.17763.8511
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over
7.5
HIGH
CVE-2026-23673
< 10.0.17763.8511
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-23672
< 10.0.17763.8511
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2026-23671
< 10.0.17763.8511
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Dr
7.0
HIGH
CVE-2026-23669
< 10.0.17763.8511
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
8.8
HIGH
CVE-2026-23668
< 10.0.17763.8511
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows
7.0
HIGH
CVE-2026-21533
< 10.0.17763.8389
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-21525
< 10.0.17763.8389
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
6.2
MEDIUM
CVE-2026-21519
< 10.0.17763.8389
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate p
7.8
HIGH
CVE-2026-21513
< 10.0.17763.8389
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
8.8
HIGH
CVE-2026-21510
< 10.0.17763.8389
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
8.8
HIGH
CVE-2026-21508
< 10.0.17763.8389
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-21255
< 10.0.17763.8389
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
8.8
HIGH
CVE-2026-21253
< 10.0.17763.8389
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2026-21251
< 10.0.17763.8389
Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-21249
< 10.0.17763.8389
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
3.3
LOW
CVE-2026-21248
< 10.0.17763.8389
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
7.3
HIGH
CVE-2026-21247
< 10.0.17763.8389
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
7.3
HIGH
CVE-2026-21246
< 10.0.17763.8389
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-21244
< 10.0.17763.8389
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
7.3
HIGH
CVE-2026-21243
< 10.0.17763.8389
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service o
7.5
HIGH
CVE-2026-21240
< 10.0.17763.8389
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-21239
< 10.0.17763.8389
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-21238
< 10.0.17763.8389
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges local
7.8
HIGH
CVE-2026-21236
< 10.0.17763.8389
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges lo
7.8
HIGH
CVE-2026-21235
< 10.0.17763.8389
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2026-21234
< 10.0.17763.8389
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform
7.0
HIGH
CVE-2026-21231
< 10.0.17763.8389
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized
7.8
HIGH
CVE-2026-21222
< 10.0.17763.8389
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-20846
< 10.0.17763.8389
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
7.5
HIGH
CVE-2026-21265
< 10.0.17763.8276
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration,
6.4
MEDIUM
CVE-2026-20962
< 10.0.17763.8276
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose informatio
4.4
MEDIUM
CVE-2026-20940
< 10.0.17763.8276
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20939
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-20937
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-20936
< 10.0.17763.8276
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
4.3
MEDIUM
CVE-2026-20934
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
7.5
HIGH
CVE-2026-20932
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-20931
< 10.0.17763.8276
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adj
8.0
HIGH
CVE-2026-20929
< 10.0.17763.8276
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2026-20927
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
5.3
MEDIUM
CVE-2026-20926
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
7.5
HIGH
CVE-2026-20925
< 10.0.17763.8276
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2026-20924
< 10.0.17763.8276
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20923
< 10.0.17763.8276
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20922
< 10.0.17763.8276
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2026-20921
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
7.5
HIGH
CVE-2026-20919
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
7.5
HIGH
CVE-2026-20918
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20877
< 10.0.17763.8276
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20875
< 10.0.17763.8276
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny ser
7.5
HIGH
CVE-2026-20874
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20873
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20872
< 10.0.17763.8276
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2026-20869
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM)
7.0
HIGH
CVE-2026-20868
< 10.0.17763.8276
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2026-20867
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20866
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20865
< 10.0.17763.8276
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20864
< 10.0.17763.8276
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2026-20862
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclos
5.5
MEDIUM
CVE-2026-20861
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.8
HIGH
CVE-2026-20860
< 10.0.17763.8276
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorize
7.8
HIGH
CVE-2026-20858
< 10.0.17763.8276
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20857
< 10.0.17763.8276
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locall
7.8
HIGH
CVE-2026-20856
< 10.0.17763.8276
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
8.1
HIGH
CVE-2026-20852
< 10.0.17763.8276
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
7.7
HIGH
CVE-2026-20849
< 10.0.17763.8276
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a
7.5
HIGH
CVE-2026-20848
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
7.5
HIGH
CVE-2026-20847
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over
6.5
MEDIUM
CVE-2026-20844
< 10.0.17763.8276
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
7.4
HIGH
CVE-2026-20843
< 10.0.17763.8276
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges lo
7.8
HIGH
CVE-2026-20840
< 10.0.17763.8276
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2026-20839
< 10.0.17763.8276
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally
5.5
MEDIUM
CVE-2026-20837
< 10.0.17763.8276
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2026-20836
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorize
7.0
HIGH
CVE-2026-20834
< 10.0.17763.8276
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
4.6
MEDIUM
CVE-2026-20833
< 10.0.17763.8276
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally
5.5
MEDIUM
CVE-2026-20832
< 10.0.17763.8276
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2026-20831
< 10.0.17763.8276
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker t
7.8
HIGH
CVE-2026-20829
< 10.0.17763.8276
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2026-20828
< 10.0.17763.8276
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a phy
4.6
MEDIUM
CVE-2026-20827
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorize
5.5
MEDIUM
CVE-2026-20826
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWIN
7.8
HIGH
CVE-2026-20825
< 10.0.17763.8276
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
4.4
MEDIUM
CVE-2026-20824
< 10.0.17763.8276
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
5.5
MEDIUM
CVE-2026-20823
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2026-20822
< 10.0.17763.8276
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20821
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to dis
6.2
MEDIUM
CVE-2026-20820
< 10.0.17763.8276
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20818
< 10.0.17763.8276
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally
6.2
MEDIUM
CVE-2026-20816
< 10.0.17763.8276
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally
7.8
HIGH
CVE-2026-20814
< 10.0.17763.8276
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorize
7.0
HIGH
CVE-2026-20812
< 10.0.17763.8276
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tamperi
6.5
MEDIUM
CVE-2026-20810
< 10.0.17763.8276
Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege
7.8
HIGH
CVE-2026-20809
< 10.0.17763.8276
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges loc
7.8
HIGH
CVE-2026-20805
< 10.0.17763.8276
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose in
5.5
MEDIUM
CVE-2026-20804
< 10.0.17763.8276
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
7.7
HIGH
CVE-2026-0386
< 10.0.17763.8276
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
7.5
HIGH
CVE-2025-64680
< 10.0.17763.7919
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-64679
< 10.0.17763.7919
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-64678
< 10.0.17763.8027
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-64673
< 10.0.17763.8146
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-64661
< 10.0.17763.8146
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized
7.8
HIGH
CVE-2025-64658
< 10.0.17763.8146
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized
7.5
HIGH
CVE-2025-62573
< 10.0.17763.8146
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-62571
< 10.0.17763.8146
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62567
< 10.0.17763.8146
Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
5.3
MEDIUM
CVE-2025-62565
< 10.0.17763.8146
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-62549
< 10.0.17763.8146
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code
8.8
HIGH
CVE-2025-62474
< 10.0.17763.8146
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62473
< 10.0.17763.8146
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-62472
< 10.0.17763.8146
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-62470
< 10.0.17763.8146
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62467
< 10.0.17763.8146
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62466
< 10.0.17763.8146
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62464
< 10.0.17763.8146
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62462
< 10.0.17763.8146
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62461
< 10.0.17763.8146
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62458
< 10.0.17763.8146
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62457
< 10.0.17763.8146
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62455
< 10.0.17763.8146
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62454
< 10.0.17763.8146
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62221
< 10.0.17763.8146
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59517
< 10.0.17763.8146
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59516
< 10.0.17763.8146
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges loc
7.8
HIGH
CVE-2025-55233
< 10.0.17763.8146
Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54100
< 10.0.17763.8146
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized a
7.8
HIGH
CVE-2025-62452
< 10.0.17763.8027
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-62217
< 10.0.17763.8027
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver f
7.0
HIGH
CVE-2025-62215
< 10.0.17763.8027
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized
7.0
HIGH
CVE-2025-62213
< 10.0.17763.8027
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-62209
< 10.0.17763.7919
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-62208
< 10.0.17763.7919
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-60724
< 10.0.17763.8027
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2025-60723
< 10.0.17763.8027
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorize
6.3
MEDIUM
CVE-2025-60720
< 10.0.17763.8027
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60719
< 10.0.17763.8027
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges
7.0
HIGH
CVE-2025-60717
< 10.0.17763.8027
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-60716
< 10.0.17763.8027
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-60715
< 10.0.17763.8027
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-60714
< 10.0.17763.8027
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-60713
< 10.0.17763.8027
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privile
7.8
HIGH
CVE-2025-60709
< 10.0.17763.8027
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60708
< 10.0.17763.8027
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
6.5
MEDIUM
CVE-2025-60707
< 10.0.17763.8027
Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60706
< 10.0.17763.8027
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-60705
< 10.0.17763.8027
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60704
< 10.0.17763.8027
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-60703
< 10.0.17763.8027
Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59515
< 10.0.17763.8027
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-59514
< 10.0.17763.8027
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59513
< 10.0.17763.8027
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-59512
< 10.0.17763.8027
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-59511
< 10.0.17763.8027
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59510
< 10.0.17763.8027
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an autho
5.5
MEDIUM
CVE-2025-59509
< 10.0.17763.8027
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-59508
< 10.0.17763.8027
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized
7.0
HIGH
CVE-2025-59507
< 10.0.17763.8027
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized
7.0
HIGH
CVE-2025-59506
< 10.0.17763.8027
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorize
7.0
HIGH
CVE-2025-59505
< 10.0.17763.8027
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59502
< 10.0.17763.7792
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
7.5
HIGH
CVE-2025-59295
< 10.0.17763.7919
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-59294
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose inf
2.1
LOW
CVE-2025-59287
< 10.0.17763.7922
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2025-59282
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unautho
7.0
HIGH
CVE-2025-59280
< 10.0.17763.7919
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
3.1
LOW
CVE-2025-59278
< 10.0.17763.7919
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2025-59277
< 10.0.17763.7919
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2025-59275
< 10.0.17763.7919
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2025-59260
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attac
5.5
MEDIUM
CVE-2025-59259
< 10.0.17763.7919
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny servic
6.5
MEDIUM
CVE-2025-59258
< 10.0.17763.7919
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclo
6.2
MEDIUM
CVE-2025-59255
< 10.0.17763.7919
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59254
< 10.0.17763.7919
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59253
< 10.0.17763.7919
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
5.5
MEDIUM
CVE-2025-59244
< 10.0.17763.7919
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2025-59242
< 10.0.17763.7919
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges lo
7.8
HIGH
CVE-2025-59230
< 10.0.17763.7919
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59214
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spo
6.5
MEDIUM
CVE-2025-59211
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disc
5.5
MEDIUM
CVE-2025-59209
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disc
5.5
MEDIUM
CVE-2025-59208
< 10.0.17763.7919
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
7.1
HIGH
CVE-2025-59207
< 10.0.17763.7919
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59205
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows
7.0
HIGH
CVE-2025-59204
< 10.0.17763.7919
Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-59203
< 10.0.17763.7919
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose informat
5.5
MEDIUM
CVE-2025-59202
< 10.0.17763.7919
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-59201
< 10.0.17763.7919
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59200
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows
7.7
HIGH
CVE-2025-59199
< 10.0.17763.7919
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59198
< 10.0.17763.7919
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
5.0
MEDIUM
CVE-2025-59197
< 10.0.17763.7919
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information loca
5.5
MEDIUM
CVE-2025-59196
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an auth
7.0
HIGH
CVE-2025-59195
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows
7.0
HIGH
CVE-2025-59193
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows
7.0
HIGH
CVE-2025-59192
< 10.0.17763.7919
Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59191
< 10.0.17763.7919
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-59190
< 10.0.17763.7919
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
5.5
MEDIUM
CVE-2025-59188
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose i
5.5
MEDIUM
CVE-2025-59187
< 10.0.17763.7919
Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59186
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-59185
< 10.0.17763.7919
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2025-59184
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to
5.5
MEDIUM
CVE-2025-58739
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spo
6.5
MEDIUM
CVE-2025-58738
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58737
< 10.0.17763.7919
Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58736
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58735
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58734
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58733
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58732
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58730
< 10.0.17763.7919
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58729
< 10.0.17763.7919
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny servic
6.5
MEDIUM
CVE-2025-58728
< 10.0.17763.7919
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-58726
< 10.0.17763.7919
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-58725
< 10.0.17763.7919
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-58722
< 10.0.17763.7919
Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-58720
< 10.0.17763.7919
Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to di
7.8
HIGH
CVE-2025-58719
< 10.0.17763.7919
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
4.7
MEDIUM
CVE-2025-58718
< 10.0.17763.7919
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-58717
< 10.0.17763.7919
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-58716
< 10.0.17763.7919
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
8.8
HIGH
CVE-2025-58715
< 10.0.17763.7919
Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
8.8
HIGH
CVE-2025-58714
< 10.0.17763.7919
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges local
7.8
HIGH
CVE-2025-55701
< 10.0.17763.7919
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-55700
< 10.0.17763.7919
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-55699
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-55696
< 10.0.17763.7919
Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to
7.8
HIGH
CVE-2025-55695
< 10.0.17763.7919
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-55692
< 10.0.17763.7919
Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-55687
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS
7.4
HIGH
CVE-2025-55683
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-55681
< 10.0.17763.7919
Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-55680
< 10.0.17763.7919
Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to eleva
7.8
HIGH
CVE-2025-55679
< 10.0.17763.7919
Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.
5.1
MEDIUM
CVE-2025-55678
< 10.0.17763.7919
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-55338
< 10.0.17763.7919
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physica
6.1
MEDIUM
CVE-2025-55336
< 10.0.17763.7919
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker
5.5
MEDIUM
CVE-2025-55335
< 10.0.17763.7919
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
7.4
HIGH
CVE-2025-55333
< 10.0.17763.7919
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with
6.1
MEDIUM
CVE-2025-55332
< 10.0.17763.7919
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with
6.1
MEDIUM
CVE-2025-55328
< 10.0.17763.7919
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorize
7.8
HIGH
CVE-2025-55326
< 10.0.17763.7919
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
7.5
HIGH
CVE-2025-55325
< 10.0.17763.7919
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-53150
< 10.0.17763.7919
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-50175
< 10.0.17763.7919
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-50152
< 10.0.17763.7919
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49708
< 10.0.17763.7919
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
9.9
CRITICAL
CVE-2025-48813
< 10.0.17763.7919
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
6.3
MEDIUM
CVE-2025-25004
< 10.0.17763.7919
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-24990
< 10.0.17763.7919
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating s
7.8
HIGH
CVE-2025-24052
< 10.0.17763.7919
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating s
7.8
HIGH
CVE-2025-55236
< 10.0.17763.7792
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.
7.3
HIGH
CVE-2025-55234
< 10.0.17763.7792
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vuln
8.8
HIGH
CVE-2025-55226
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorize
6.7
MEDIUM
CVE-2025-55225
< 10.0.17763.7792
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-55224
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.8
HIGH
CVE-2025-55223
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorize
7.0
HIGH
CVE-2025-54919
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.5
HIGH
CVE-2025-54918
< 10.0.17763.7792
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-54917
< 10.0.17763.7792
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
4.3
MEDIUM
CVE-2025-54916
< 10.0.17763.7792
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2025-54915
< 10.0.17763.7792
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54913
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSett
7.8
HIGH
CVE-2025-54912
< 10.0.17763.7792
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54911
< 10.0.17763.7792
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-54895
< 10.0.17763.7792
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54894
< 10.0.17763.7792
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2025-54116
< 10.0.17763.7792
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-54115
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorize
7.0
HIGH
CVE-2025-54113
< 10.0.17763.7792
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-54112
< 10.0.17763.7792
Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-54111
< 10.0.17763.7792
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54110
< 10.0.17763.7792
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
8.8
HIGH
CVE-2025-54109
< 10.0.17763.7792
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54107
< 10.0.17763.7792
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over
4.3
MEDIUM
CVE-2025-54106
< 10.0.17763.7792
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code
8.8
HIGH
CVE-2025-54104
< 10.0.17763.7792
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54102
< 10.0.17763.7792
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54101
< 10.0.17763.7792
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
4.8
MEDIUM
CVE-2025-54099
< 10.0.17763.7792
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges l
7.0
HIGH
CVE-2025-54098
< 10.0.17763.7792
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54097
< 10.0.17763.7792
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54096
< 10.0.17763.7792
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54095
< 10.0.17763.7792
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54094
< 10.0.17763.7792
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54093
< 10.0.17763.7792
Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-54092
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorize
7.8
HIGH
CVE-2025-54091
< 10.0.17763.7792
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-53810
< 10.0.17763.7792
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-53808
< 10.0.17763.7792
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-53807
< 10.0.17763.7792
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows
7.0
HIGH
CVE-2025-53806
< 10.0.17763.7792
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-53804
< 10.0.17763.7792
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-53803
< 10.0.17763.7792
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose informati
5.5
MEDIUM
CVE-2025-53801
< 10.0.17763.7792
Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-53800
< 10.0.17763.7792
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-53799
< 10.0.17763.7792
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-53798
< 10.0.17763.7792
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-53797
< 10.0.17763.7792
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-53796
< 10.0.17763.7792
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-49734
< 10.0.17763.7792
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate
7.0
HIGH
CVE-2025-55231
< 10.0.17763.7783
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthori
7.5
HIGH
CVE-2025-55230
< 10.0.17763.7558
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-55229
< 10.0.17763.7314
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over
5.3
MEDIUM
CVE-2025-53789
< 10.0.17763.7558
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges lo
7.8
HIGH
CVE-2025-53778
< 10.0.17763.7678
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-53766
< 10.0.17763.7678
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2025-53726
< 10.0.17763.7678
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to eleva
7.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin