Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2025-60709

Windows Common Log File System Driver Elevation of Privilege Vulnerability_MS:CVE-2025-60709

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.8 MS:CVE-2025-62449

Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability_MS:CVE-2025-62449

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized at...

N/A N/A MSCVE
HIGH 8.7 MS:CVE-2025-62211

Dynamics 365 Field Service (online) Spoofing Vulnerability_MS:CVE-2025-62211

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized at...

N/A N/A MSCVE
HIGH 8 MS:CVE-2025-62204

Microsoft SharePoint Remote Code Execution Vulnerability_MS:CVE-2025-62204

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2025-62201

Microsoft Excel Remote Code Execution Vulnerability_MS:CVE-2025-62201

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
CRITICAL 9.8 MS:CVE-2025-60724

GDI+ Remote Code Execution Vulnerability_MS:CVE-2025-60724

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2025-60720

Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability_MS:CVE-2025-60720

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 5.5 MS:CVE-2025-59240

Microsoft Excel Information Disclosure Vulnerability_MS:CVE-2025-59240

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2025-62220

Windows Subsystem for Linux GUI Remote Code Execution Vulnerability_MS:CVE-2025-62220

Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-62217

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2025-62217

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows...

N/A N/A MSCVE