Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2025-03-11 CVE-2025-24983 Use After Free vulnerability in Microsoft products
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
local
high complexity
microsoft CWE-416
7.0
2025-03-11 CVE-2025-24985 Heap-based Buffer Overflow vulnerability in Microsoft products
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
local
low complexity
microsoft CWE-122
7.8
2025-03-11 CVE-2025-24993 Heap-based Buffer Overflow vulnerability in Microsoft products
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
local
low complexity
microsoft CWE-122
7.8
2025-03-11 CVE-2025-26633 Improper Enforcement of Message or Data Structure vulnerability in Microsoft products
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
local
high complexity
microsoft CWE-707
7.0
2025-02-11 CVE-2025-21182 Unspecified vulnerability in Microsoft Windows 11 24H2 and Windows Server 2025
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
local
high complexity
microsoft
7.4
2025-02-11 CVE-2025-21183 Unspecified vulnerability in Microsoft Windows 11 24H2 and Windows Server 2025
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
local
high complexity
microsoft
7.4
2025-02-11 CVE-2025-21184 Unspecified vulnerability in Microsoft products
Windows Core Messaging Elevation of Privileges Vulnerability
local
high complexity
microsoft
7.0
2025-02-11 CVE-2025-21190 Unspecified vulnerability in Microsoft products
Windows Telephony Service Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8
2025-02-11 CVE-2025-21200 Unspecified vulnerability in Microsoft products
Windows Telephony Service Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8
2025-02-11 CVE-2025-21201 Unspecified vulnerability in Microsoft products
Windows Telephony Server Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8