Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 MS:CVE-2025-60705

Windows Client-Side Caching Elevation of Privilege Vulnerability_MS:CVE-2025-60705

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
MEDIUM 5.5 MS:CVE-2025-59513

Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability_MS:CVE-2025-59513

Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2025-59512

Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability_MS:CVE-2025-59512

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2025-59511

Windows WLAN Service Elevation of Privilege Vulnerability_MS:CVE-2025-59511

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.3 MS:CVE-2025-59504

Azure Monitor Agent Remote Code Execution Vulnerability_MS:CVE-2025-59504

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-60719

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability_MS:CVE-2025-60719

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE
HIGH 7.8 MS:CVE-2025-62216

Microsoft Office Remote Code Execution Vulnerability_MS:CVE-2025-62216

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-59506

DirectX Graphics Kernel Elevation of Privilege Vulnerability_MS:CVE-2025-59506

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to ele...

N/A N/A MSCVE
HIGH 8.1 MS:CVE-2025-30398

Nuance PowerScribe 360 Information Disclosure Vulnerability_MS:CVE-2025-30398

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 7 MS:CVE-2025-62219

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability_MS:CVE-2025-62219

Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

N/A N/A MSCVE