CVE-2025-49689
- EPSS 0.1%
- Published 08.07.2025 16:57:15
- Last modified 15.07.2025 17:31:37
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49687
- EPSS 0.07%
- Published 08.07.2025 16:57:14
- Last modified 15.07.2025 17:33:18
Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-49686
- EPSS 0.07%
- Published 08.07.2025 16:57:13
- Last modified 15.07.2025 17:25:09
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2025-49661
- EPSS 0.07%
- Published 08.07.2025 16:57:09
- Last modified 15.07.2025 14:52:27
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-49658
- EPSS 0.06%
- Published 08.07.2025 16:57:08
- Last modified 15.07.2025 14:53:47
Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
CVE-2025-47986
- EPSS 0.07%
- Published 08.07.2025 16:57:06
- Last modified 14.07.2025 17:38:02
Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47987
- EPSS 0.09%
- Published 08.07.2025 16:57:06
- Last modified 14.07.2025 17:38:41
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
CVE-2025-47985
- EPSS 0.07%
- Published 08.07.2025 16:57:05
- Last modified 14.07.2025 17:37:35
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
CVE-2025-47976
- EPSS 0.07%
- Published 08.07.2025 16:57:04
- Last modified 14.07.2025 17:28:17
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47984
- EPSS 0.19%
- Published 08.07.2025 16:57:04
- Last modified 14.07.2025 17:36:17
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.