CVE-2025-21374 – Windows CSC Service Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-21374
14 Jan 2025 — Windows CSC Service Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21374 • CWE-125: Out-of-bounds Read •
CVE-2025-21339 – Windows Telephony Service Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-21339
14 Jan 2025 — Windows Telephony Service Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21339 • CWE-122: Heap-based Buffer Overflow •
CVE-2025-21338 – GDI+ Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-21338
14 Jan 2025 — GDI+ Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21338 • CWE-190: Integer Overflow or Wraparound •
CVE-2025-21336 – Windows Cryptographic Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-21336
14 Jan 2025 — Windows Cryptographic Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21336 •
CVE-2025-21331 – Windows Installer Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-21331
14 Jan 2025 — Windows Installer Elevation of Privilege Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer service. By creating a mount point, an attacker can abuse the service to delete arbitrary files. An attacker can leverage this vulnerability to escalate pri... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21331 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2025-21324 – Windows Digital Media Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-21324
14 Jan 2025 — Windows Digital Media Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21324 • CWE-125: Out-of-bounds Read •
CVE-2025-21323 – Windows Kernel Memory Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-21323
14 Jan 2025 — Windows Kernel Memory Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21323 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2025-21312 – Windows Smart Card Reader Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-21312
14 Jan 2025 — Windows Smart Card Reader Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21312 • CWE-908: Use of Uninitialized Resource •
CVE-2025-21310 – Windows Digital Media Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-21310
14 Jan 2025 — Windows Digital Media Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21310 • CWE-125: Out-of-bounds Read •
CVE-2025-21308 – Windows Themes Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2025-21308
14 Jan 2025 — Windows Themes Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21308 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •