cbcvebase.

Microsoft Windows Server 2025 vulnerabilities

1,706 known vulnerabilities affecting microsoft/windows_server_2025.

Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
46
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9

Vulnerabilities

Page 49 of 86
CVE-2026-20812P3MEDIUMCVSS 6.5fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20812 [MEDIUM] CWE-20 CVE-2026-20812: Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authoriz Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
nvd
CVE-2024-43625P3HIGHCVSS 8.1fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-43625 [HIGH] CWE-416 CVE-2024-43625: Microsoft Windows VMSwitch Elevation of Privilege Vulnerability Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
nvd
CVE-2024-49076P3HIGHCVSS 7.8fixed in 10.0.26100.2605≥ 10.0.26100.0, < 10.0.26100.26052024-12-12
CVE-2024-49076 [HIGH] CWE-287 CVE-2024-49076: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
nvd
CVE-2024-49079P3HIGHCVSS 7.8fixed in 10.0.26100.2605≥ 10.0.26100.0, < 10.0.26100.26052024-12-12
CVE-2024-49079 [HIGH] CWE-416 CVE-2024-49079: Input Method Editor (IME) Remote Code Execution Vulnerability Input Method Editor (IME) Remote Code Execution Vulnerability
nvd
CVE-2025-55698P3HIGHCVSS 7.7≤ 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-55698 [HIGH] CWE-476 CVE-2025-55698: Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a net Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.
nvd
CVE-2025-21358P3HIGHCVSS 7.8fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21358 [HIGH] CWE-822 CVE-2025-21358: Windows Core Messaging Elevation of Privileges Vulnerability Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2024-43626P3HIGHCVSS 7.8fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-43626 [HIGH] CWE-122 CVE-2024-43626: Windows Telephony Service Elevation of Privilege Vulnerability Windows Telephony Service Elevation of Privilege Vulnerability
nvd
CVE-2025-49689P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-21367P3HIGHCVSS 7.8fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21367 [HIGH] CWE-416 CVE-2025-21367: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2025-53805P3HIGHCVSS 7.5fixed in 10.0.26100.6508≥ 10.0.26100.0, < 10.0.26100.65842025-09-09
CVE-2025-53805 [HIGH] CWE-125 CVE-2025-53805: Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21378P3HIGHCVSS 7.8fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43644P3HIGHCVSS 7.8fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-43644 [HIGH] CWE-125 CVE-2024-43644: Windows Client-Side Caching Elevation of Privilege Vulnerability Windows Client-Side Caching Elevation of Privilege Vulnerability
nvd
CVE-2024-43646P3HIGHCVSS 7.8fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-43646 [HIGH] CWE-822 CVE-2024-43646: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43631P3HIGHCVSS 7.8fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-43631 [HIGH] CWE-822 CVE-2024-43631: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2026-25190P3HIGHCVSS 7.8fixed in 10.0.26100.32463≥ 10.0.26100.0, < 10.0.26100.325222026-03-10
CVE-2026-25190 [HIGH] CWE-426 CVE-2026-25190: Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59194P3HIGHCVSS 7.0≤ 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-59194 [HIGH] CWE-908 CVE-2025-59194: Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2025-49694P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49694 [HIGH] CWE-476 CVE-2025-49694: Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49686P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49686 [HIGH] CWE-476 CVE-2025-49686: Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges local Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47985P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-47985 [HIGH] CWE-822 CVE-2025-47985: Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate priv Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows Server 2025 vulnerabilities | cvebase