Microsoft

Windows 11 25h2

1816 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.8%
  • Veröffentlicht 11.11.2025 18:15:40
  • Zuletzt bearbeitet 17.11.2025 17:40:11

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network.

Warnung Medienbericht
  • EPSS 4.6%
  • Veröffentlicht 11.11.2025 18:15:39
  • Zuletzt bearbeitet 14.04.2026 14:44:19

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

  • EPSS 0.79%
  • Veröffentlicht 11.11.2025 18:15:39
  • Zuletzt bearbeitet 17.11.2025 17:43:02

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 11.11.2025 18:15:39
  • Zuletzt bearbeitet 17.11.2025 17:42:54

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • EPSS 0.33%
  • Veröffentlicht 11.11.2025 18:15:39
  • Zuletzt bearbeitet 17.11.2025 17:42:50

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • EPSS 0.53%
  • Veröffentlicht 11.11.2025 18:15:38
  • Zuletzt bearbeitet 17.11.2025 17:47:15

Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

  • EPSS 2.41%
  • Veröffentlicht 11.11.2025 18:15:38
  • Zuletzt bearbeitet 17.11.2025 17:47:11

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

  • EPSS 0.47%
  • Veröffentlicht 11.11.2025 18:15:38
  • Zuletzt bearbeitet 17.11.2025 17:47:07

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

  • EPSS 0.49%
  • Veröffentlicht 11.11.2025 18:15:38
  • Zuletzt bearbeitet 16.12.2025 18:16:13

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

  • EPSS 0.46%
  • Veröffentlicht 11.11.2025 18:15:38
  • Zuletzt bearbeitet 17.11.2025 17:47:26

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.