Vulnerabilities > Microsoft > Windows Server 2016 > High

DATE CVE VULNERABILITY TITLE RISK
2025-05-13 CVE-2025-29840 Stack-based Buffer Overflow vulnerability in Microsoft products
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
network
low complexity
microsoft CWE-121
8.8
2025-05-13 CVE-2025-29842 Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in Microsoft products
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
network
high complexity
microsoft CWE-349
7.5
2025-05-13 CVE-2025-29962 Heap-based Buffer Overflow vulnerability in Microsoft products
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
network
low complexity
microsoft CWE-122
8.8
2025-05-13 CVE-2025-29966 Heap-based Buffer Overflow vulnerability in Microsoft products
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
network
low complexity
microsoft CWE-122
8.8
2025-05-13 CVE-2025-29967 Heap-based Buffer Overflow vulnerability in Microsoft products
Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
network
low complexity
microsoft CWE-122
8.8
2025-05-13 CVE-2025-29969 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Microsoft products
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
network
high complexity
microsoft CWE-367
7.5
2025-05-13 CVE-2025-29976 Improper Privilege Management vulnerability in Microsoft products
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
local
low complexity
microsoft CWE-269
7.8
2025-04-08 CVE-2025-29824 Use After Free vulnerability in Microsoft products
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
local
low complexity
microsoft CWE-416
7.8
2025-03-11 CVE-2025-24983 Use After Free vulnerability in Microsoft products
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
local
high complexity
microsoft CWE-416
7.0
2025-03-11 CVE-2025-24993 Heap-based Buffer Overflow vulnerability in Microsoft products
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
local
low complexity
microsoft CWE-122
7.8