CVE-2025-21205
- EPSS 0.09%
- Veröffentlicht 08.04.2025 17:23:37
- Zuletzt bearbeitet 10.07.2025 15:53:24
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
- EPSS 0.04%
- Veröffentlicht 08.04.2025 17:23:36
- Zuletzt bearbeitet 07.07.2025 18:57:42
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
CVE-2025-21197
- EPSS 0.21%
- Veröffentlicht 08.04.2025 17:23:36
- Zuletzt bearbeitet 10.07.2025 15:52:05
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
CVE-2025-29824
- EPSS 1.19%
- Veröffentlicht 08.04.2025 17:23:34
- Zuletzt bearbeitet 27.10.2025 17:14:21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-27742
- EPSS 0.06%
- Veröffentlicht 08.04.2025 17:23:22
- Zuletzt bearbeitet 10.07.2025 15:12:31
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
CVE-2025-27741
- EPSS 0.08%
- Veröffentlicht 08.04.2025 17:23:21
- Zuletzt bearbeitet 10.07.2025 15:11:22
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-27740
- EPSS 0.4%
- Veröffentlicht 08.04.2025 17:23:20
- Zuletzt bearbeitet 10.07.2025 15:08:52
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
- EPSS 0.05%
- Veröffentlicht 08.04.2025 17:23:19
- Zuletzt bearbeitet 08.07.2025 19:12:54
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
CVE-2025-27477
- EPSS 0.23%
- Veröffentlicht 08.04.2025 17:23:18
- Zuletzt bearbeitet 08.07.2025 19:12:30
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27474
- EPSS 0.21%
- Veröffentlicht 08.04.2025 17:23:17
- Zuletzt bearbeitet 08.07.2025 19:11:07
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.