CVE-2025-21333 – Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2025-21333
14 Jan 2025 — Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21333 • CWE-122: Heap-based Buffer Overflow •
CVE-2025-21332 – MapUrlToZone Security Feature Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2025-21332
14 Jan 2025 — MapUrlToZone Security Feature Bypass Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21332 • CWE-41: Improper Resolution of Path Equivalence •
CVE-2025-21378 – Windows CSC Service Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-21378
14 Jan 2025 — Windows CSC Service Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21378 • CWE-122: Heap-based Buffer Overflow •
CVE-2025-21374 – Windows CSC Service Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-21374
14 Jan 2025 — Windows CSC Service Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21374 • CWE-125: Out-of-bounds Read •
CVE-2025-21340 – Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2025-21340
14 Jan 2025 — Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21340 • CWE-284: Improper Access Control •
CVE-2025-21339 – Windows Telephony Service Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-21339
14 Jan 2025 — Windows Telephony Service Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21339 • CWE-122: Heap-based Buffer Overflow •
CVE-2025-21338 – GDI+ Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-21338
14 Jan 2025 — GDI+ Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21338 • CWE-190: Integer Overflow or Wraparound •
CVE-2025-21336 – Windows Cryptographic Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-21336
14 Jan 2025 — Windows Cryptographic Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21336 •
CVE-2025-21331 – Windows Installer Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-21331
14 Jan 2025 — Windows Installer Elevation of Privilege Vulnerability This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer service. By creating a mount point, an attacker can abuse the service to delete arbitrary files. An attacker can leverage this vulnerability to escalate pri... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21331 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2025-21324 – Windows Digital Media Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-21324
14 Jan 2025 — Windows Digital Media Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21324 • CWE-125: Out-of-bounds Read •