Microsoft

Windows Server 2025

2593 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 1.2%
  • Veröffentlicht 08.09.2026 17:14:01
  • Zuletzt bearbeitet 24.09.2026 23:18:37

Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 08.09.2026 17:14:01
  • Zuletzt bearbeitet 10.09.2026 14:56:55

Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 08.09.2026 17:13:55
  • Zuletzt bearbeitet 24.09.2026 23:19:11

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally.

Medienbericht Exploit
  • EPSS 0.34%
  • Veröffentlicht 08.09.2026 17:13:54
  • Zuletzt bearbeitet 10.09.2026 15:13:19

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.23%
  • Veröffentlicht 08.09.2026 17:13:53
  • Zuletzt bearbeitet 10.09.2026 15:14:14

Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.

Medienbericht
  • EPSS 0.87%
  • Veröffentlicht 08.09.2026 17:13:51
  • Zuletzt bearbeitet 24.09.2026 23:19:09

Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.

Medienbericht
  • EPSS 0.46%
  • Veröffentlicht 08.09.2026 17:13:44
  • Zuletzt bearbeitet 24.09.2026 23:19:07

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 08.09.2026 17:13:34
  • Zuletzt bearbeitet 24.09.2026 23:19:04

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 08.09.2026 17:13:31
  • Zuletzt bearbeitet 28.09.2026 20:06:03

Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.

Medienbericht
  • EPSS 0.16%
  • Veröffentlicht 08.09.2026 17:13:30
  • Zuletzt bearbeitet 24.09.2026 23:19:03

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.