CVE-2025-54116
- EPSS 0.04%
- Published 09.09.2025 17:01:26
- Last modified 02.10.2025 18:03:02
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
- EPSS 0.04%
- Published 09.09.2025 17:01:25
- Last modified 02.10.2025 18:02:19
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to deny service locally.
- EPSS 0.05%
- Published 09.09.2025 17:01:24
- Last modified 01.10.2025 20:17:04
Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
CVE-2025-54109
- EPSS 0.16%
- Published 09.09.2025 17:01:23
- Last modified 02.10.2025 14:36:32
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
CVE-2025-54107
- EPSS 0.07%
- Published 09.09.2025 17:01:22
- Last modified 02.10.2025 16:33:56
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- EPSS 0.04%
- Published 09.09.2025 17:01:22
- Last modified 02.10.2025 14:36:24
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2025-54104
- EPSS 0.16%
- Published 09.09.2025 17:01:21
- Last modified 02.10.2025 16:27:57
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- EPSS 0.04%
- Published 09.09.2025 17:01:21
- Last modified 02.10.2025 16:28:07
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-54098
- EPSS 0.06%
- Published 09.09.2025 17:01:20
- Last modified 02.10.2025 16:56:20
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-54103
- EPSS 0.05%
- Published 09.09.2025 17:01:20
- Last modified 02.10.2025 17:10:58
Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.