CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Microsoft Windows Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in Microsoft Windows, allowing an authorized attacker to locally elevate privileges. This vulnerability affects several Windows versions and stems from improper memory management, which can be exploited to gain higher system privileges.
Microsoft Windows Kernel Buffer Over-read Vulnerability Allowing Information Disclosure
A buffer over-read vulnerability has been identified in the Windows Kernel. This issue allows an authorized attacker to locally disclose information. The vulnerability affects multiple Windows products, including various versions of Windows Server, Windows 10, and Windows 11.
Microsoft Windows File Explorer Information Disclosure Vulnerability
A vulnerability in Windows File Explorer allows an authorized attacker to locally disclose sensitive information to an unauthorized actor. This issue is present in several versions of Windows.
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability Allowing Local Code Execution
A heap-based buffer overflow vulnerability has been identified in the Windows NTFS file system. This vulnerability allows an unauthorized attacker to execute code locally. The issue arises from improper handling of memory, which can be exploited to overwrite adjacent memory and potentially execute arbitrary code.
Microsoft Windows Network Policy Server SNMP Out-of-Bounds Read Vulnerability Allowing Information Disclosure
A vulnerability allowing out-of-bounds read has been identified in the SNMP implementation of Windows Network Policy Server. This issue allows an unauthorized attacker to disclose information over the network by reading portions of process memory. The vulnerability affects multiple Windows Server and Windows 10 versions.
Microsoft Windows Projected File System Elevation of Privilege Vulnerability
A vulnerability in the Windows Projected File System allows an authorized attacker to elevate privileges locally by improperly resolving links before file access. This 'link following' issue could enable the attacker to delete system files.
Microsoft SQL Server Buffer Over-Read Vulnerability Allowing Information Disclosure
A buffer over-read vulnerability has been identified in Microsoft SQL Server. This issue allows an authorized attacker to disclose information by reading small portions of heap memory over the network. The vulnerability affects several versions of SQL Server, including SQL Server 2025, 2022, 2019, and 2017, as well as SQL Server 2016 with the Azure Connect Feature Pack.
Microsoft Office Use-After-Free Vulnerability Allowing Local Code Execution
A use-after-free vulnerability has been identified in Microsoft Office, which allows an unauthorized attacker to execute code locally. This vulnerability affects multiple Office products, including Office 2016, Office 2019, Office LTSC 2021, Office 365 for Mac, and various editions of Microsoft 365 Apps for Enterprise. The vulnerability arises from improper memory management, leading to a use-after-free condition that can be exploited to execute arbitrary code.
Microsoft Windows Brokering File System Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the Windows Brokering File System, allowing an authorized attacker to locally elevate privileges. This vulnerability affects multiple versions of Windows 11 and Windows Server 2025.
Microsoft Windows DNS Improper Access Control Vulnerability Allowing Local Tampering
A vulnerability has been identified in Microsoft Windows DNS that involves improper access control. This flaw allows an authorized attacker to manipulate DNS settings or data locally. The issue arises from inadequate restrictions on user permissions, enabling unauthorized modifications by users with certain privileges.
Microsoft Windows Kernel Out-of-Bounds Read Vulnerability Allowing Information Disclosure
A vulnerability allowing out-of-bounds read has been identified in the Windows Kernel. This issue could enable an unauthorized attacker to disclose information over a network, specifically by reading the contents of Kernel memory from a user mode process.
Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability
A vulnerability in the Windows Ancillary Function Driver for WinSock allows an authorized attacker to gain elevated privileges locally. This issue arises from external control of file names or paths, which could be exploited to manipulate file handling in a way that increases the attacker's privileges.
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability Allowing Local Remote Code Execution
A heap-based buffer overflow vulnerability has been identified in the Windows NTFS file system. This vulnerability allows an unauthorized attacker to execute code locally. The issue arises when a user mounts a specially crafted virtual hard disk (VHD) file, which can lead to the execution of malicious code on the system.
Microsoft Windows Runtime Elevation of Privilege Vulnerability
A race condition vulnerability has been identified in Windows Runtime, allowing an unauthorized attacker to elevate privileges over a network. This issue arises from concurrent execution using shared resources with improper synchronization.
Microsoft Windows Kernel Privilege Escalation Vulnerability
A use-after-free vulnerability in the Windows Kernel has been identified, allowing an unauthorized attacker to locally elevate privileges. This vulnerability affects multiple versions of Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025. The vulnerability arises from a use-after-free condition, which can be exploited to gain SYSTEM privileges.
Microsoft Brokering File System Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the Microsoft Brokering File System, allowing an authorized attacker to locally elevate privileges. This issue arises from improper memory management, creating opportunities for exploitation.
Microsoft Windows Runtime Privilege Elevation Vulnerability
A use-after-free vulnerability has been identified in Windows Runtime, allowing an authorized attacker to locally elevate privileges. This vulnerability affects several versions of Windows 10, Windows 11, and Windows Server 2019 and 2025. The issue arises from improper memory management, which could be exploited to gain higher privileges, potentially up to SYSTEM level.
Microsoft Windows File Explorer Information Disclosure Vulnerability
A vulnerability in Windows File Explorer allows an authorized attacker to disclose sensitive information locally. This issue affects several versions of Windows 10, Windows 11, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2025, and Windows Server 2022. The vulnerability arises from the exposure of sensitive information to an unauthorized actor, potentially leaking the address of a medium integrity process to a lower integrity caller process.
Microsoft Universal Plug and Play Information Disclosure Vulnerability
A vulnerability in Universal Plug and Play (UPnP) within the 'upnp.dll' file allows an authorized attacker to locally disclose information. This issue arises from the use of uninitialized resources, which could enable a non-administrator attacker to read files accessible to the UPnP Device Host Service. The vulnerability affects several versions of Windows, including various releases of Windows 10, Windows 11, Windows Server 2012, 2016, 2019, 2022, and 2025, as well as Windows Server 2012 R2 and 2025 Server Core installations.
Microsoft Windows User Interface Core Relative Path Traversal Privilege Escalation Vulnerability
A relative path traversal vulnerability has been identified in Windows User Interface Core, allowing an authorized attacker to locally elevate privileges. This vulnerability affects multiple versions of Windows 11 and Windows Server 2025.
Microsoft Windows USB Audio Class Driver Information Disclosure Vulnerability
A vulnerability allowing out-of-bounds read has been identified in the Windows USB Audio Class driver (usbaudio.sys). This issue could enable an unauthorized attacker to disclose information, but it requires a physical attack to exploit.
Microsoft Windows Runtime Elevation of Privilege Vulnerability
A race condition vulnerability has been identified in Windows Runtime, allowing an unauthorized attacker to elevate privileges over a network. This issue arises from concurrent execution using shared resources with improper synchronization.
Microsoft Windows RRAS Privilege Escalation Vulnerability
A vulnerability in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to locally elevate privileges. This issue arises from missing authentication for critical functions within RRAS.
Microsoft Windows Wireless Wide Area Network Service Privilege Escalation Vulnerability
A race condition vulnerability has been identified in the Windows Wireless Wide Area Network Service, allowing an authorized attacker to locally elevate privileges. This issue arises from concurrent execution using shared resources without proper synchronization.
Microsoft Windows Runtime Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in Windows Runtime, allowing an authorized attacker to locally elevate privileges. This vulnerability affects multiple Windows 10 and Windows 11 versions, as well as Windows Server 2019 and 2022.
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability Allowing Local Code Execution
A heap-based buffer overflow vulnerability has been identified in the Windows NTFS file system. This vulnerability allows an unauthorized attacker to execute code locally. The issue arises from improper handling of memory, which can be exploited to overwrite adjacent memory and potentially execute arbitrary code.
Microsoft Windows Message Queuing Heap-Based Buffer Overflow Vulnerability Allowing Remote Code Execution
A heap-based buffer overflow vulnerability has been identified in the Windows Message Queuing (MSMQ) service. This vulnerability allows an unauthorized attacker to execute code remotely over the network. The issue arises when the system improperly handles specially crafted requests containing maliciously formed domain names, leading to memory corruption that could be exploited for further compromise of the affected system.
Microsoft Windows RDP Buffer Over-Read Vulnerability Allowing Information Disclosure
A buffer over-read vulnerability has been identified in the Remote Desktop Protocol (RDP) implementation of Microsoft Windows. This vulnerability allows an unauthorized attacker to disclose information over the network by exploiting the buffer over-read condition, which can potentially lead to unauthorized access to sensitive data.
Microsoft Windows Server Update Service Privilege Escalation Vulnerability
A vulnerability in Windows Server Update Service (WSUS) allows an authorized attacker to elevate privileges over the network due to missing authentication for a critical function. This issue affects multiple Windows Server and Windows 10 versions.
Microsoft Windows File Explorer Information Disclosure Vulnerability
A vulnerability in Windows File Explorer allows an authorized attacker to locally disclose sensitive information to an unauthorized actor. This issue affects several versions of Windows and is rooted in the improper handling of server object addresses, which could be exposed during normal file exploration activities.
Microsoft Windows Resilient File System Privilege Escalation Vulnerability
A vulnerability allowing untrusted pointer dereference has been identified in the Windows Resilient File System (ReFS). This flaw enables an authorized attacker to locally elevate privileges. The issue affects multiple versions of Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025.
Microsoft Windows Audio Service Race Condition Vulnerability Allowing Privilege Escalation
A race condition vulnerability has been identified in the Windows Audio Service, allowing authorized attackers to elevate privileges locally. This issue arises from concurrent execution using shared resources without proper synchronization.
Microsoft Message Queuing Queue Manager Use-After-Free Vulnerability Allowing Remote Code Execution
A use-after-free vulnerability has been identified in the Microsoft Message Queuing Queue Manager. This vulnerability allows an unauthorized attacker to execute code remotely over the network. It affects multiple Windows versions, including various Windows 10 releases, Windows 11, Windows Server 2012, 2016, 2019, 2022, and 2025, as well as Windows Server 2012 R2 and 2025 Server Core installations.
Microsoft PC Manager Elevation of Privilege Vulnerability
A vulnerability allowing local privilege escalation has been identified in Microsoft PC Manager. This issue arises from improper link resolution before file access, a flaw that could be exploited by an authorized attacker.
Microsoft Windows DWM Core Library Out-of-Bounds Read Vulnerability Allowing Information Disclosure
A vulnerability allowing out-of-bounds read has been identified in the Windows DWM Core Library. This issue allows an authorized attacker to locally disclose information by reading portions of heap memory.
Microsoft Windows Kernel Privilege Escalation Vulnerability
A use-after-free vulnerability in the Windows Kernel has been identified, allowing an authorized attacker to locally elevate privileges. This vulnerability could enable an attacker to gain SYSTEM privileges.
Microsoft Windows Overlay Filter Privilege Escalation Vulnerability
A buffer over-read vulnerability has been identified in the Windows Overlay Filter, allowing an authorized attacker to locally elevate privileges. This issue affects multiple Windows 10 versions, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022.
Microsoft Windows Push Notifications Information Disclosure Vulnerability
A vulnerability in Windows Push Notifications allows an authorized attacker to disclose sensitive information locally. This issue arises from the exposure of information to an unauthorized actor, potentially leaking the address of a medium integrity process to a lower integrity caller process.
Microsoft Windows Media Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in Windows Media, allowing an authorized attacker to locally elevate privileges. This vulnerability affects multiple Windows versions and stems from improper memory management, which can be exploited to gain higher system privileges.
Microsoft Windows Virtual Filtering Platform Denial-of-Service Vulnerability
A use-after-free vulnerability has been identified in the Windows Virtual Filtering Platform (VFP), allowing an authorized attacker to cause a denial-of-service condition over the network. This vulnerability affects multiple Windows 10 and Windows 11 versions, as well as several Windows Server releases.
Microsoft Windows QoS Packet Scheduler Information Disclosure Vulnerability
An information disclosure vulnerability has been identified in the Windows Quality of Service (QoS) Packet Scheduler. This vulnerability allows the disclosure of certain memory addresses within kernel space. An attacker could potentially leverage this information for malicious activities. The vulnerability affects multiple Windows products and versions, including Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, as well as various versions of Windows 10 and Windows 11.
Microsoft Windows Push Notifications Information Disclosure Vulnerability
A vulnerability in Windows Push Notifications allows an authorized attacker to disclose sensitive information locally. This issue affects several versions of Windows 10, Windows 11, Windows Server 2016, Windows Server 2025, and Windows Server 2022. The vulnerability could leak the address of a medium integrity process to a lower integrity caller process.
Microsoft Windows Kernel Out-of-Bounds Read Vulnerability Allowing Information Disclosure
A vulnerability allowing out-of-bounds read has been identified in the Windows Kernel. This issue could enable an unauthorized attacker to disclose information over a network, specifically by reading contents of Kernel memory from a user mode process.
Microsoft Windows Container Isolation FS Filter Driver Information Disclosure Vulnerability
A vulnerability allowing out-of-bounds read has been identified in the Windows Container Isolation FS Filter Driver (unionfs.sys). This issue allows an authorized attacker to locally disclose information by exploiting the vulnerability, which could involve accessing certain kernel memory content.
Microsoft Content Delivery Manager Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in Microsoft Content Delivery Manager, allowing an authorized attacker to locally elevate privileges. This vulnerability affects several versions of Windows 10, Windows 11, and Windows Server 2019 and 2025.
Microsoft Windows DNS Server Relative Path Traversal Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Windows DNS Server. This issue arises from relative path traversal, which allows an authorized attacker to execute code on a system over an adjacent network. The vulnerability affects multiple versions of Windows Server and Windows 10.
Microsoft Windows Internal System User Profile Privilege Escalation Vulnerability
A use-after-free vulnerability has been identified in the Windows Internal System User Profile component. This vulnerability allows an authorized attacker to elevate privileges locally. It affects multiple versions of Windows 10 and Windows 11, as well as Windows Server 2025.
Microsoft Windows Domain Controller Untrusted Pointer Dereference Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Windows Domain Controller. This issue arises from an untrusted pointer dereference, which allows an unauthorized attacker to disrupt services over the network.
Microsoft Windows Kernel Elevation of Privilege Vulnerability
A vulnerability in the Windows Kernel has been identified, allowing an authorized attacker to elevate privileges locally. This issue arises from improper access control within the kernel.
Microsoft Windows NTFS Privilege Escalation Vulnerability
A vulnerability allowing out-of-bounds read in Windows NTFS has been identified, which could enable an authorized attacker to locally elevate privileges. This issue affects multiple Windows versions, including various releases of Windows 10, Windows 11, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025. The vulnerability arises from improper handling of memory, allowing attackers to access restricted areas and potentially gain SYSTEM privileges.
