CVE-2025-59516
- EPSS 2.29%
- Veröffentlicht 09.12.2025 17:55:47
- Zuletzt bearbeitet 07.10.2026 11:10:00
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-59517
- EPSS 2.33%
- Veröffentlicht 09.12.2025 17:55:47
- Zuletzt bearbeitet 07.10.2026 11:10:00
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-64673
- EPSS 0.33%
- Veröffentlicht 09.12.2025 17:55:46
- Zuletzt bearbeitet 10.12.2025 19:07:21
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-64670
- EPSS 0.98%
- Veröffentlicht 09.12.2025 17:55:45
- Zuletzt bearbeitet 10.12.2025 19:10:34
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
- EPSS 0.24%
- Veröffentlicht 09.12.2025 17:55:43
- Zuletzt bearbeitet 10.12.2025 19:17:02
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2025-64658
- EPSS 0.31%
- Veröffentlicht 09.12.2025 17:55:43
- Zuletzt bearbeitet 25.09.2026 23:10:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2025-62572
- EPSS 0.39%
- Veröffentlicht 09.12.2025 17:55:42
- Zuletzt bearbeitet 10.12.2025 19:20:43
Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2025-62571
- EPSS 0.39%
- Veröffentlicht 09.12.2025 17:55:41
- Zuletzt bearbeitet 10.12.2025 19:21:02
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2025-62473
- EPSS 1.05%
- Veröffentlicht 09.12.2025 17:55:38
- Zuletzt bearbeitet 07.10.2026 11:10:00
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-62549
- EPSS 1.29%
- Veröffentlicht 09.12.2025 17:55:38
- Zuletzt bearbeitet 07.10.2026 11:10:00
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.