Vulnerabilities > Microsoft > Windows Server 2022 > 10.0.20348.946

DATE CVE VULNERABILITY TITLE RISK
2025-05-13 CVE-2025-27468 Improper Privilege Management vulnerability in Microsoft products
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
local
high complexity
microsoft CWE-269
7.0
2025-05-13 CVE-2025-29829 Use of Uninitialized Resource vulnerability in Microsoft products
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
local
low complexity
microsoft CWE-908
5.5
2025-05-13 CVE-2025-29830 Use of Uninitialized Resource vulnerability in Microsoft products
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-908
6.5
2025-05-13 CVE-2025-29831 Use After Free vulnerability in Microsoft products
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
network
high complexity
microsoft CWE-416
7.5
2025-05-13 CVE-2025-29832 Out-of-bounds Read vulnerability in Microsoft products
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-125
6.5
2025-05-13 CVE-2025-29835 NULL Pointer Dereference vulnerability in Microsoft products
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-476
6.5
2025-05-13 CVE-2025-29836 Out-of-bounds Read vulnerability in Microsoft products
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-125
6.5
2025-05-13 CVE-2025-29837 Link Following vulnerability in Microsoft products
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
local
low complexity
microsoft CWE-59
5.5
2025-05-13 CVE-2025-29839 Out-of-bounds Read vulnerability in Microsoft products
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
local
low complexity
microsoft CWE-125
4.0
2025-05-13 CVE-2025-29840 Stack-based Buffer Overflow vulnerability in Microsoft products
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
network
low complexity
microsoft CWE-121
8.8