Windows Server (General) · Top 20

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Microsoft CVE-2025-62473 CVSS 6.5 2025-12-09 08:00 UTC · 2025-12-09 05:00 -03

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Microsoft CVE-2025-62549 CVSS 8.8 2025-12-09 08:00 UTC · 2025-12-09 05:00 -03

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

Microsoft CVE-2025-62567 CVSS 5.3 2025-12-09 08:00 UTC · 2025-12-09 05:00 -03

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Microsoft CVE-2025-64678 CVSS 8.8 2025-12-09 08:00 UTC · 2025-12-09 05:00 -03

Information published.

Microsoft CVE-2025-59775 CVSS 7.5 2025-12-07 01:03 UTC · 2025-12-06 22:03 -03

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.

Microsoft CVE-2025-59510 CVSS 5.5 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-60703 CVSS 7.8 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

Microsoft CVE-2025-60704 CVSS 7.5 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

Microsoft CVE-2025-60706 CVSS 5.5 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-60713 CVSS 7.8 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Microsoft CVE-2025-60715 CVSS 8.0 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-60719 CVSS 7.0 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-62213 CVSS 7.0 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-62217 CVSS 7.0 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Microsoft CVE-2025-62452 CVSS 8.0 2025-11-11 08:00 UTC · 2025-11-11 05:00 -03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-55328 CVSS 7.8 2025-10-14 07:00 UTC · 2025-10-14 04:00 -03

Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Microsoft CVE-2025-55335 CVSS 7.4 2025-10-14 07:00 UTC · 2025-10-14 04:00 -03

Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

Microsoft CVE-2025-55340 CVSS 7.0 2025-10-14 07:00 UTC · 2025-10-14 04:00 -03

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Microsoft CVE-2025-55700 CVSS 6.5 2025-10-14 07:00 UTC · 2025-10-14 04:00 -03

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft CVE-2025-58714 CVSS 7.8 2025-10-14 07:00 UTC · 2025-10-14 04:00 -03