CVE-2025-49723
- EPSS 0.06%
- Published 08.07.2025 16:57:23
- Last modified 16.07.2025 17:38:08
Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
CVE-2025-49726
- EPSS 0.07%
- Published 08.07.2025 16:57:23
- Last modified 16.07.2025 17:31:41
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2025-49721
- EPSS 0.08%
- Published 08.07.2025 16:57:22
- Last modified 16.07.2025 17:37:11
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49716
- EPSS 9.38%
- Published 08.07.2025 16:57:21
- Last modified 16.07.2025 17:36:20
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
CVE-2025-47991
- EPSS 0.06%
- Published 08.07.2025 16:57:17
- Last modified 14.07.2025 17:39:38
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-49690
- EPSS 0.05%
- Published 08.07.2025 16:57:16
- Last modified 15.07.2025 17:31:11
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
- EPSS 0.15%
- Published 08.07.2025 16:57:16
- Last modified 15.07.2025 17:29:20
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
CVE-2025-49689
- EPSS 0.1%
- Published 08.07.2025 16:57:15
- Last modified 15.07.2025 17:31:37
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49687
- EPSS 0.07%
- Published 08.07.2025 16:57:14
- Last modified 15.07.2025 17:33:18
Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-49688
- EPSS 0.08%
- Published 08.07.2025 16:57:14
- Last modified 15.07.2025 17:32:18
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.