Filtered by vendor Microsoft
Subscribe
Total
22989 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-62455 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 5 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-55233 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-59516 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-64785 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not requ ...
Show More |
|||||
| CVE-2025-64786 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2025-12-12 | N/A | 3.3 LOW |
|
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited unauthorized write access. Exploitation of this issue does not require user interaction.
|
|||||
| CVE-2025-64787 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2025-12-12 | N/A | 3.3 LOW |
|
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass cryptographic protections and gain limited unauthorized write access. Exploitation of this issue does not require user interaction.
|
|||||
| CVE-2025-64899 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
|
|||||
| CVE-2025-64669 | 1 Microsoft | 1 Windows Admin Center | 2025-12-12 | N/A | 7.8 HIGH |
|
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-64671 | 1 Microsoft | 1 Github Copilot | 2025-12-12 | N/A | 8.4 HIGH |
|
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.
|
|||||
| CVE-2025-64672 | 1 Microsoft | 1 Sharepoint Server | 2025-12-12 | N/A | 8.8 HIGH |
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-64679 | 1 Microsoft | 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-64680 | 1 Microsoft | 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more | 2025-12-12 | N/A | 7.8 HIGH |
|
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-59286 | 1 Microsoft | 1 365 Copilot Chat | 2025-12-11 | N/A | 9.3 CRITICAL |
|
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
|
|||||
| CVE-2025-59272 | 1 Microsoft | 1 365 Copilot Chat | 2025-12-11 | N/A | 9.3 CRITICAL |
|
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
|
|||||
| CVE-2025-59252 | 1 Microsoft | 1 365 Word Copilot | 2025-12-11 | N/A | 9.3 CRITICAL |
|
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
|
|||||
| CVE-2025-62223 | 1 Microsoft | 1 Edge Chromium | 2025-12-10 | N/A | 4.3 MEDIUM |
|
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-62459 | 1 Microsoft | 1 365 Defender Portal | 2025-12-10 | N/A | 8.3 HIGH |
|
Microsoft Defender Portal Spoofing Vulnerability
|
|||||
| CVE-2025-64655 | 1 Microsoft | 1 Dynamics Omnichannel Sdk Storage Containers | 2025-12-10 | N/A | 8.8 HIGH |
|
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
|
|||||
| CVE-2025-62567 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2025-12-10 | N/A | 5.3 MEDIUM |
|
Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
|
|||||
| CVE-2025-62550 | 1 Microsoft | 1 Azure Monitor Agent | 2025-12-10 | N/A | 8.8 HIGH |
|
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
|
|||||
| CVE-2025-62570 | 1 Microsoft | 3 Windows 11 24h2, Windows 11 25h2, Windows Server 2025 | 2025-12-10 | N/A | 7.1 HIGH |
|
Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.
|
|||||
| CVE-2025-62571 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-62572 | 1 Microsoft | 3 Windows 11 24h2, Windows 11 25h2, Windows Server 2025 | 2025-12-10 | N/A | 7.8 HIGH |
|
Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-62573 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2025-12-10 | N/A | 7.0 HIGH |
|
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-64661 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-64670 | 1 Microsoft | 8 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 5 more | 2025-12-10 | N/A | 6.5 MEDIUM |
|
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
|
|||||
| CVE-2025-64673 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-64678 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2025-12-10 | N/A | 8.8 HIGH |
|
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
|
|||||
| CVE-2025-62461 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-62462 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-62463 | 1 Microsoft | 8 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 5 more | 2025-12-10 | N/A | 6.5 MEDIUM |
|
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
|
|||||
| CVE-2025-62464 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
|
|||||
| CVE-2025-62465 | 1 Microsoft | 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2025-12-10 | N/A | 6.5 MEDIUM |
|
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
|
|||||
| CVE-2025-62554 | 1 Microsoft | 3 365 Apps, Office, Office Long Term Servicing Channel | 2025-12-10 | N/A | 8.4 HIGH |
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
|
|||||
| CVE-2025-62555 | 1 Microsoft | 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more | 2025-12-10 | N/A | 7.0 HIGH |
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
|||||
| CVE-2025-64783 | 3 Adobe, Apple, Microsoft | 3 Dng Software Development Kit, Macos, Windows | 2025-12-10 | N/A | 7.8 HIGH |
|
DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
|
|||||
| CVE-2025-64784 | 3 Adobe, Apple, Microsoft | 3 Dng Software Development Kit, Macos, Windows | 2025-12-10 | N/A | 7.1 HIGH |
|
DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
|
|||||
| CVE-2025-64893 | 3 Adobe, Apple, Microsoft | 3 Dng Software Development Kit, Macos, Windows | 2025-12-10 | N/A | 7.1 HIGH |
|
DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
|
|||||
| CVE-2025-64894 | 3 Adobe, Apple, Microsoft | 3 Dng Software Development Kit, Macos, Windows | 2025-12-10 | N/A | 5.5 MEDIUM |
|
DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this issue to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
|
|||||
| CVE-2025-62556 | 1 Microsoft | 5 365 Apps, Excel, Office and 2 more | 2025-12-10 | N/A | 7.8 HIGH |
|
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
|||||