CVE-2025-54918
- EPSS 0.1%
- Published 09.09.2025 17:01:00
- Last modified 02.10.2025 14:52:16
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-54913
- EPSS 0.04%
- Published 09.09.2025 17:00:59
- Last modified 02.10.2025 14:41:09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
CVE-2025-54895
- EPSS 0.06%
- Published 09.09.2025 17:00:52
- Last modified 02.10.2025 18:03:20
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
CVE-2025-54111
- EPSS 0.05%
- Published 09.09.2025 17:00:51
- Last modified 01.10.2025 20:00:39
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
CVE-2025-54894
- EPSS 0.05%
- Published 09.09.2025 17:00:51
- Last modified 02.10.2025 18:03:12
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2025-54110
- EPSS 0.09%
- Published 09.09.2025 17:00:50
- Last modified 01.10.2025 19:56:19
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-54102
- EPSS 0.05%
- Published 09.09.2025 17:00:49
- Last modified 02.10.2025 15:01:04
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
CVE-2025-54101
- EPSS 0.05%
- Published 09.09.2025 17:00:48
- Last modified 02.10.2025 17:10:51
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
- EPSS 0.05%
- Published 09.09.2025 17:00:47
- Last modified 02.10.2025 16:56:33
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- EPSS 0.04%
- Published 09.09.2025 17:00:41
- Last modified 02.10.2025 18:45:04
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.