CVE-2025-26642
Last Modified: 13 Feb 2026Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-26637
Last Modified: 16 Feb 2026Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2025-26635
Last Modified: 13 Feb 2026Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
CVE-2025-26639
Last Modified: 13 Feb 2026Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-26628
Last Modified: 13 Feb 2026Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.
CVE-2025-25002
Last Modified: 13 Feb 2026Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
CVE-2025-24058
Last Modified: 13 Feb 2026Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-21222
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-21221
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-21204
Last Modified: 13 Feb 2026Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2025-21203
Last Modified: 13 Feb 2026Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-21205
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-21191
Last Modified: 13 Feb 2026Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
CVE-2025-21197
Last Modified: 13 Feb 2026Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
CVE-2025-21174
Last Modified: 13 Feb 2026Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
CVE-2025-24073
Last Modified: 13 Feb 2026Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-24074
Last Modified: 13 Feb 2026Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-29824
Last Modified: 13 Feb 2026Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-29823
Last Modified: 13 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29822
Last Modified: 13 Feb 2026Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-29820
Last Modified: 13 Feb 2026Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-29821
Last Modified: 13 Feb 2026Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
CVE-2025-29794
Last Modified: 13 Feb 2026Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-29792
Last Modified: 13 Feb 2026Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2025-29793
Last Modified: 13 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-29791
Last Modified: 13 Feb 2026Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27750
Last Modified: 13 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27752
Last Modified: 13 Feb 2026Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27751
Last Modified: 13 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27743
Last Modified: 13 Feb 2026Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
CVE-2025-27749
Last Modified: 13 Feb 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27747
Last Modified: 13 Feb 2026Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-27748
Last Modified: 13 Feb 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27746
Last Modified: 13 Feb 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27745
Last Modified: 13 Feb 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27742
Last Modified: 13 Feb 2026Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
CVE-2025-27744
Last Modified: 13 Feb 2026Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2025-27741
Last Modified: 13 Feb 2026Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-27740
Last Modified: 13 Feb 2026Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
CVE-2025-27479
Last Modified: 13 Feb 2026Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
CVE-2025-27478
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
CVE-2025-27477
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27475
Last Modified: 13 Feb 2026Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2025-27476
Last Modified: 13 Feb 2026Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-27474
Last Modified: 13 Feb 2026Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-27472
Last Modified: 13 Feb 2026Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-27473
Last Modified: 13 Feb 2026Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
CVE-2025-27470
Last Modified: 13 Feb 2026Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
CVE-2025-27471
Last Modified: 13 Feb 2026Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
CVE-2025-26688
Last Modified: 13 Feb 2026Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
