Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-04-08 CVE-2025-26647 Improper input validation in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
8.8
2025-04-08 CVE-2025-26649 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
local
high complexity
CWE-416
7.0
2025-04-08 CVE-2025-26651 Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
network
low complexity
CWE-749
6.5
2025-04-08 CVE-2025-26652 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
network
low complexity
CWE-400
7.5
2025-04-08 CVE-2025-26664 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
CWE-126
6.5
2025-04-08 CVE-2025-26666 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
local
low complexity
CWE-122
7.8
2025-04-08 CVE-2025-26667 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
CWE-200
6.5
2025-04-08 CVE-2025-26671 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
network
high complexity
CWE-591
8.1
2025-04-08 CVE-2025-26674 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
local
low complexity
CWE-122
7.8
2025-04-08 CVE-2025-26675 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-125
7.8