CVE Alert: CVE-2025-59287 – Microsoft – Windows Server 2019
CVE-2025-59287 CRITICALExploitation active Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over...
CVE-2025-59287 CRITICALExploitation active Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over...
CVE-2025-33073 HIGHCISA KEVExploitation active Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network....
CVE-2025-55335 HIGHNo exploitation known Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-55328 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized...
CVE-2025-55331 HIGHNo exploitation known Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-55339 HIGHNo exploitation known Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. CVSS v3.1 (7.8)...
CVE-2025-55326 HIGHNo exploitation known Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code...
CVE-2025-53150 HIGHNo exploitation known Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-53139 HIGHNo exploitation known Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security...
CVE-2025-50174 HIGHNo exploitation known Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges...
CVE-2025-48004 HIGHNo exploitation known Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally....
CVE-2025-50175 HIGHNo exploitation known Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-50152 HIGHNo exploitation known Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. CVSS v3.1 (7.8)...
CVE-2025-24052 HIGHNo exploitation known Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with...
CVE-2025-25004 HIGHNo exploitation known Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. CVSS v3.1...
CVE-2025-59230 HIGHExploitation active Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally....
CVE-2025-24990 HIGHExploitation active Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported...
CVE-2025-59216 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an...
CVE-2025-59220 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an...
CVE-2025-59215 HIGHNo exploitation known Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-54110 HIGHNo exploitation known Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. CVSS...
CVE-2025-54106 HIGHNo exploitation known Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker...
CVE-2025-54111 HIGHNo exploitation known Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges...
CVE-2025-54108 HIGHNo exploitation known Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc)...
