CVE Vulnerabilities for "product:windows_11_25h2"

Showing 1-10 of 92 CVEs (filtered from 316,443 total)

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

HIGH 8.8
EPSS 0.1%
10/14/2025
2025

Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.

LOW 2.1
EPSS 0.1%
10/14/2025
2025

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

LOW 3.3
EPSS 0.0%
10/14/2025
2025

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

HIGH 7
EPSS 0.1%
10/14/2025
2025

Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

HIGH 7
EPSS 0.0%
10/14/2025
2025

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

MEDIUM 6.5
EPSS 0.2%
10/14/2025
2025

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

MEDIUM 6.5
EPSS 0.2%
10/14/2025
2025

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.0%
10/14/2025
2025

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.0%
10/14/2025
2025

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

MEDIUM 5.5
EPSS 0.0%
10/14/2025
2025
Page 1 of 2