Microsoft Windows Server 2025 vulnerabilities
1,706 known vulnerabilities affecting microsoft/windows_server_2025.
Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
46
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9
Vulnerabilities
Page 13 of 86
CVE-2025-21273P3HIGHCVSS 8.8fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21273 [HIGH] CWE-122 CVE-2025-21273: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21282P3HIGHCVSS 8.8fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21282 [HIGH] CWE-122 CVE-2025-21282: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-27481P3HIGHCVSS 8.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-27481 [HIGH] CWE-121 CVE-2025-27481: Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45602P3CRITICALCVSS 9.1fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-45602 [CRITICAL] CWE-349 CVE-2026-45602: No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering ov
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2026-32225P3HIGHCVSS 8.8fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-32225 [HIGH] CWE-693 CVE-2026-32225: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-53131P3HIGHCVSS 8.8fixed in 10.0.26100.4851≥ 10.0.26100.0, < 10.0.26100.49462025-08-12
CVE-2025-53131 [HIGH] CWE-122 CVE-2025-53131: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-26663P3HIGHCVSS 8.1fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-26663 [HIGH] CWE-416 CVE-2025-26663: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21294P3HIGHCVSS 8.1fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-40415P3HIGHCVSS 8.1fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-40415 [HIGH] CWE-416 CVE-2026-40415: Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45635P3HIGHCVSS 8.1fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-45635 [HIGH] CWE-843 CVE-2026-45635: Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll)
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45599P3HIGHCVSS 8.1fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-45599 [HIGH] CWE-416 CVE-2026-45599: Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21311P3CRITICALCVSS 9.8fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21311 [CRITICAL] CWE-303 CVE-2025-21311: Windows NTLM V1 Elevation of Privilege Vulnerability
Windows NTLM V1 Elevation of Privilege Vulnerability
nvd
CVE-2025-21204P3HIGHCVSS 7.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33829P4MEDIUMCVSS 4.3PoCfixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-33829 [MEDIUM] CWE-200 CVE-2026-33829: Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauth
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-24289P3HIGHCVSS 7.8fixed in 10.0.26100.32463≥ 10.0.26100.0, < 10.0.26100.325222026-03-10
CVE-2026-24289 [HIGH] CWE-416 CVE-2026-24289: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24056P3HIGHCVSS 8.8fixed in 10.0.26100.3403fixed in 10.0.26100.3476+1 more2025-03-11
CVE-2025-24056 [HIGH] CWE-122 CVE-2025-24056: Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute co
Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-20871P3HIGHCVSS 7.8fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20871 [HIGH] CWE-416 CVE-2026-20871: Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locall
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21222P3HIGHCVSS 8.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-21222 [HIGH] CWE-122 CVE-2025-21222: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21221P3HIGHCVSS 8.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-21221 [HIGH] CWE-122 CVE-2025-21221: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21205P3HIGHCVSS 8.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-21205 [HIGH] CWE-122 CVE-2025-21205: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd