Microsoft

Windows Server 2025

1915 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 08.07.2025 16:57:03
  • Zuletzt bearbeitet 14.07.2025 17:21:11

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.

  • EPSS 0.46%
  • Veröffentlicht 08.07.2025 16:57:02
  • Zuletzt bearbeitet 14.07.2025 17:29:00

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

  • EPSS 0.37%
  • Veröffentlicht 08.07.2025 16:57:00
  • Zuletzt bearbeitet 14.07.2025 17:30:26

Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

  • EPSS 0.86%
  • Veröffentlicht 08.07.2025 16:56:59
  • Zuletzt bearbeitet 14.07.2025 15:18:37

Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.

  • EPSS 0.42%
  • Veröffentlicht 08.07.2025 16:56:58
  • Zuletzt bearbeitet 14.07.2025 15:16:47

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.

  • EPSS 6.98%
  • Veröffentlicht 10.06.2025 17:02:35
  • Zuletzt bearbeitet 08.07.2025 15:04:13

Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.

Warnung Medienbericht
  • EPSS 80.42%
  • Veröffentlicht 10.06.2025 17:02:35
  • Zuletzt bearbeitet 27.10.2025 17:12:42

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

  • EPSS 1.56%
  • Veröffentlicht 10.06.2025 17:02:34
  • Zuletzt bearbeitet 10.07.2025 15:59:47

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

  • EPSS 0.29%
  • Veröffentlicht 10.06.2025 17:02:34
  • Zuletzt bearbeitet 10.07.2025 16:01:08

Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

  • EPSS 1.48%
  • Veröffentlicht 10.06.2025 17:02:33
  • Zuletzt bearbeitet 10.07.2025 16:03:28

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.