Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 MS:CVE-2025-10200

Chromium: CVE-2025-10200 Use after free in Serviceworker_MS:CVE-2025-10200

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2025-10201

Chromium: CVE-2025-10201 Inappropriate implementation in Mojo_MS:CVE-2025-10201

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-54114

Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability_MS:CVE-2025-54114

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an...

N/A N/A MSCVE
HIGH 7.3 MS:CVE-2025-54911

Windows BitLocker Elevation of Privilege Vulnerability_MS:CVE-2025-54911

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-54108

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability_MS:CVE-2025-54108

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows...

N/A N/A MSCVE
HIGH 8.4 MS:CVE-2025-54910

Microsoft Office Remote Code Execution Vulnerability_MS:CVE-2025-54910

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7.3 MS:CVE-2025-54116

Windows MultiPoint Services Elevation of Privilege Vulnerability_MS:CVE-2025-54116

Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2025-53809

Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability_MS:CVE-2025-53809

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

N/A N/A MSCVE
MEDIUM 6.7 MS:CVE-2025-54109

Windows Defender Firewall Service Elevation of Privilege Vulnerability_MS:CVE-2025-54109

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privile...

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-53807

Windows Graphics Component Elevation of Privilege Vulnerability_MS:CVE-2025-53807

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized at...

N/A N/A MSCVE