Microsoft Windows Server 2025 vulnerabilities
1,706 known vulnerabilities affecting microsoft/windows_server_2025.
Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
46
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9
Vulnerabilities
Page 44 of 86
CVE-2025-33068P3HIGHCVSS 7.5fixed in 10.0.26100.4270≥ 10.0.26100.0, < 10.0.26100.43492025-06-10
CVE-2025-33068 [HIGH] CWE-400 CVE-2025-33068: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-29812P3HIGHCVSS 7.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-29812 [HIGH] CWE-822 CVE-2025-29812: Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate priv
Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20875P3HIGHCVSS 7.5fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20875 [HIGH] CWE-476 CVE-2026-20875: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-33056P3HIGHCVSS 7.5fixed in 10.0.26100.4270≥ 10.0.26100.0, < 10.0.26100.43492025-06-10
CVE-2025-33056 [HIGH] CWE-284 CVE-2025-33056: Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26677P3HIGHCVSS 7.5fixed in 10.0.26100.4061≥ 10.0.26100.0, < 10.0.26100.40612025-05-13
CVE-2025-26677 [HIGH] CWE-400 CVE-2025-26677: Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker
Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21375P3HIGHCVSS 7.8fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21375 [HIGH] CWE-20 CVE-2025-21375: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-27476P3HIGHCVSS 7.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-27476 [HIGH] CWE-416 CVE-2025-27476: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27467P3HIGHCVSS 7.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-27467 [HIGH] CWE-416 CVE-2025-27467: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27730P3HIGHCVSS 7.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-27730 [HIGH] CWE-415 CVE-2025-27730: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45654P3HIGHCVSS 7.9fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-45654 [HIGH] CWE-284 CVE-2026-45654: Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security fe
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-24044P3HIGHCVSS 7.8fixed in 10.0.26100.3403≥ 10.0.26100.0, < 10.0.26100.34762025-03-11
CVE-2025-24044 [HIGH] CWE-416 CVE-2025-24044: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26679P3HIGHCVSS 7.8fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-26679 [HIGH] CWE-416 CVE-2025-26679: Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges lo
Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-33075P3HIGHCVSS 7.8fixed in 10.0.26100.4270≥ 10.0.26100.0, < 10.0.26100.43492025-06-10
CVE-2025-33075 [HIGH] CWE-59 CVE-2025-33075: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-44812P3HIGHCVSS 7.8fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-44812 [HIGH] CWE-190 CVE-2026-44812: Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-44803P3HIGHCVSS 7.8fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-44803 [HIGH] CWE-190 CVE-2026-44803: Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24072P3HIGHCVSS 7.8fixed in 10.0.26100.3403≥ 10.0.26100.0, < 10.0.26100.34762025-03-11
CVE-2025-24072 [HIGH] CWE-416 CVE-2025-24072: Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker t
Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49667P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49667 [HIGH] CWE-415 CVE-2025-49667: Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49721P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49721 [HIGH] CWE-122 CVE-2025-49721: Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate pri
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-53800P3HIGHCVSS 7.8fixed in 10.0.26100.6508≥ 10.0.26100.0, < 10.0.26100.65842025-09-09
CVE-2025-53800 [HIGH] CWE-1419 CVE-2025-53800: No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privi
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-57095P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-57095 [HIGH] CWE-200 CVE-2026-57095: Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.
nvd