CVE Alert: CVE-2025-59287 – Microsoft – Windows Server 2019
CVE-2025-59287 CRITICALExploitation active Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over...
CVE-2025-59287 CRITICALExploitation active Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over...
CVE-2025-33073 HIGHCISA KEVExploitation active Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network....
CVE-2025-55328 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized...
CVE-2025-55331 HIGHNo exploitation known Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-55335 HIGHNo exploitation known Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-55339 HIGHNo exploitation known Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. CVSS v3.1 (7.8)...
CVE-2025-55326 HIGHNo exploitation known Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code...
CVE-2025-50175 HIGHNo exploitation known Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-50152 HIGHNo exploitation known Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. CVSS v3.1 (7.8)...
CVE-2025-24052 HIGHNo exploitation known Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with...
CVE-2025-25004 HIGHNo exploitation known Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-59230 HIGHExploitation active Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally....
CVE-2025-24990 HIGHExploitation active Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported...
CVE-2021-43226 HIGHExploitation active Windows Common Log File System Driver Elevation of Privilege Vulnerability CVSS v3.1 (7.8) Vendor Microsoft, Microsoft, Microsoft,...
CVE-2025-59220 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an...
CVE-2025-54110 HIGHNo exploitation known Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-54106 HIGHNo exploitation known Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker...
CVE-2025-54111 HIGHNo exploitation known Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges...
CVE-2025-54112 HIGHNo exploitation known Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally....
CVE-2025-54102 HIGHNo exploitation known Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges...
CVE-2025-54091 HIGHNo exploitation known Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-54092 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized...
CVE-2025-54098 HIGHNo exploitation known Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-54093 HIGHNo exploitation known Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally....