15226 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 28EXPL: 0

11 Mar 2025 — Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26645 • CWE-23: Relative Path Traversal CWE-284: Improper Access Control •

CVSS: 7.0EPSS: 0%CPEs: 26EXPL: 0

11 Mar 2025 — Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of MSC files. The product does not warn the user before loading an unexpected MSC file. An a... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633 • CWE-707: Improper Neutralization •

CVSS: 7.3EPSS: 0%CPEs: 4EXPL: 0

11 Mar 2025 — Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24994 • CWE-284: Improper Access Control •

CVSS: 7.8EPSS: 2%CPEs: 26EXPL: 0

11 Mar 2025 — Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993 • CWE-122: Heap-based Buffer Overflow •

CVSS: 5.5EPSS: 0%CPEs: 26EXPL: 0

11 Mar 2025 — Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24992 • CWE-126: Buffer Over-read •

CVSS: 5.5EPSS: 2%CPEs: 26EXPL: 0

11 Mar 2025 — Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24991 • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 7%CPEs: 26EXPL: 0

11 Mar 2025 — Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24985 • CWE-122: Heap-based Buffer Overflow CWE-190: Integer Overflow or Wraparound •

CVSS: 4.9EPSS: 16%CPEs: 21EXPL: 0

11 Mar 2025 — Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24984 • CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 7.0EPSS: 1%CPEs: 13EXPL: 0

11 Mar 2025 — Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24983 • CWE-416: Use After Free •

CVSS: 8.4EPSS: 0%CPEs: 8EXPL: 0

11 Mar 2025 — Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24084 • CWE-822: Untrusted Pointer Dereference •