Filtered by vendor Microsoft
Subscriptions
Filtered by product Windows 11
Subscriptions
Total
674 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-47981 | 1 Microsoft | 18 Windows, Windows 10, Windows 10 1507 and 15 more | 2025-09-26 | 9.8 Critical |
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | ||||
CVE-2025-59220 | 1 Microsoft | 13 Windows, Windows 10, Windows 10 21h2 and 10 more | 2025-09-25 | 7 High |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-59216 | 1 Microsoft | 5 Windows, Windows 11, Windows 11 24h2 and 2 more | 2025-09-25 | 7 High |
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-55224 | 1 Microsoft | 15 Hyper-v, Windows, Windows 10 and 12 more | 2025-09-25 | 7.8 High |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | ||||
CVE-2025-54911 | 1 Microsoft | 20 Bitlocker, Windows, Windows 10 and 17 more | 2025-09-25 | 7.3 High |
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53809 | 1 Microsoft | 5 Windows, Windows 11, Windows 11 24h2 and 2 more | 2025-09-25 | 6.5 Medium |
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | ||||
CVE-2025-8061 | 2 Lenovo, Microsoft | 3 Dispatcher, Windows, Windows 11 | 2025-09-22 | 7 High |
A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability does not affect systems when the Windows feature Core Isolation Memory Integrity is enabled. Lenovo systems preloaded with Windows 11 have this feature enabled by default. | ||||
CVE-2025-53778 | 1 Microsoft | 21 Windows, Windows 10, Windows 10 1507 and 18 more | 2025-09-17 | 8.8 High |
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||||
CVE-2025-53726 | 1 Microsoft | 21 Server, Windows, Windows 10 and 18 more | 2025-09-17 | 7.8 High |
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53725 | 1 Microsoft | 21 Server, Windows, Windows 10 and 18 more | 2025-09-17 | 7.8 High |
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53723 | 2 Microsoft, Windows | 20 Windows, Windows 10, Windows 10 1507 and 17 more | 2025-09-17 | 7.8 High |
Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53716 | 1 Microsoft | 16 Server, Windows, Windows 10 and 13 more | 2025-09-17 | 6.5 Medium |
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | ||||
CVE-2025-53155 | 1 Microsoft | 22 Server, Windows, Windows 10 and 19 more | 2025-09-17 | 7.8 High |
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53154 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2025-09-17 | 7.8 High |
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53145 | 1 Microsoft | 21 Windows, Windows 10, Windows 10 1507 and 18 more | 2025-09-17 | 8.8 High |
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||||
CVE-2025-53144 | 1 Microsoft | 20 Windows, Windows 10, Windows 10 1507 and 17 more | 2025-09-17 | 8.8 High |
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||||
CVE-2025-53143 | 1 Microsoft | 21 Windows, Windows 10, Windows 10 1507 and 18 more | 2025-09-17 | 8.8 High |
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||||
CVE-2025-53142 | 1 Microsoft | 11 Server, Windows, Windows 11 and 8 more | 2025-09-17 | 7 High |
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53140 | 1 Microsoft | 21 Windows, Windows 10, Windows 10 1507 and 18 more | 2025-09-17 | 7 High |
Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally. | ||||
CVE-2025-53135 | 1 Microsoft | 20 Directx, Windows, Windows 10 and 17 more | 2025-09-17 | 7 High |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally. |