Vulnerabilities > Microsoft > Windows Server 2022 > 10.0.20348.2402

DATE CVE VULNERABILITY TITLE RISK
2025-05-13 CVE-2025-29829 Use of Uninitialized Resource vulnerability in Microsoft products
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
local
low complexity
microsoft CWE-908
5.5
2025-05-13 CVE-2025-29830 Use of Uninitialized Resource vulnerability in Microsoft products
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-908
6.5
2025-05-13 CVE-2025-29831 Use After Free vulnerability in Microsoft products
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
network
high complexity
microsoft CWE-416
7.5
2025-05-13 CVE-2025-29832 Out-of-bounds Read vulnerability in Microsoft products
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-125
6.5
2025-05-13 CVE-2025-29835 NULL Pointer Dereference vulnerability in Microsoft products
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-476
6.5
2025-05-13 CVE-2025-29836 Out-of-bounds Read vulnerability in Microsoft products
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-125
6.5
2025-05-13 CVE-2025-29837 Link Following vulnerability in Microsoft products
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
local
low complexity
microsoft CWE-59
5.5
2025-05-13 CVE-2025-29839 Out-of-bounds Read vulnerability in Microsoft products
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
local
low complexity
microsoft CWE-125
4.0
2025-05-13 CVE-2025-29840 Stack-based Buffer Overflow vulnerability in Microsoft products
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
network
low complexity
microsoft CWE-121
8.8
2025-05-13 CVE-2025-29841 Use After Free vulnerability in Microsoft products
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
local
high complexity
microsoft CWE-416
7.0