cbcvebase.

Microsoft Windows Server 2025 vulnerabilities

1,706 known vulnerabilities affecting microsoft/windows_server_2025.

Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
46
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9

Vulnerabilities

Page 50 of 86
CVE-2025-49661P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49661 [HIGH] CWE-822 CVE-2025-49661: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55230P3HIGHCVSS 7.8fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-08-21
CVE-2025-55230 [HIGH] CWE-822 CVE-2025-55230: Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to eleva Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32071P3HIGHCVSS 7.5fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-32071 [HIGH] CWE-476 CVE-2026-32071: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27738P3MEDIUMCVSS 6.5fixed in 10.0.26100.3775≥ 10.0.26100.0, < 10.0.26100.37752025-04-08
CVE-2025-27738 [MEDIUM] CWE-284 CVE-2025-27738: Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to dis Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-35416P3HIGHCVSS 7.0fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-35416 [HIGH] CWE-416 CVE-2026-35416: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29842P3HIGHCVSS 7.5fixed in 10.0.26100.4061≥ 10.0.26100.0, < 10.0.26100.40612025-05-13
CVE-2025-29842 [HIGH] CWE-349 CVE-2025-29842: Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-54919P3HIGHCVSS 7.5fixed in 10.0.26100.6508≥ 10.0.26100.0, < 10.0.26100.65842025-09-09
CVE-2025-54919 [HIGH] CWE-362 CVE-2025-54919: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2026-27908P3HIGHCVSS 7.0fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-27908 [HIGH] CWE-416 CVE-2026-27908: Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49690P3HIGHCVSS 7.4fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49690 [HIGH] CWE-362 CVE-2025-49690: Concurrent execution using shared resource with improper synchronization ('race condition') in Capab Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-25004P3HIGHCVSS 7.3≤ 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-25004 [HIGH] CWE-284 CVE-2025-25004: Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27921P3HIGHCVSS 7.0fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-27921 [HIGH] CWE-362 CVE-2026-27921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50682P3HIGHCVSS 7.1fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50682 [HIGH] CWE-125 CVE-2026-50682: Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
nvd
CVE-2026-41108P3HIGHCVSS 7.0fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45653P3HIGHCVSS 7.0fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-45653 [HIGH] CWE-122 CVE-2026-45653: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49670P3MEDIUMCVSS 6.5fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-49670 [MEDIUM] CWE-122 CVE-2025-49670: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21373P3HIGHCVSS 7.8fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21373 [HIGH] CWE-59 CVE-2025-21373: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-43641P3HIGHCVSS 7.8fixed in 10.0.26100.2314≥ 10.0.26100.0, < 10.0.26100.23142024-11-12
CVE-2024-43641 [HIGH] CWE-190 CVE-2024-43641: Windows Registry Elevation of Privilege Vulnerability Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2024-49072P3HIGHCVSS 7.8fixed in 10.0.26100.2605≥ 10.0.26100.0, < 10.0.26100.26052024-12-12
CVE-2024-49072 [HIGH] CWE-122 CVE-2024-49072: Windows Task Scheduler Elevation of Privilege Vulnerability Windows Task Scheduler Elevation of Privilege Vulnerability
nvd
CVE-2025-21275P3HIGHCVSS 7.8fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21275 [HIGH] CWE-285 CVE-2025-21275: Windows App Package Installer Elevation of Privilege Vulnerability Windows App Package Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-49107P3HIGHCVSS 7.3fixed in 10.0.26100.2605≥ 10.0.26100.0, < 10.0.26100.26052024-12-12
CVE-2024-49107 [HIGH] CWE-59 CVE-2024-49107: WmsRepair Service Elevation of Privilege Vulnerability WmsRepair Service Elevation of Privilege Vulnerability
nvd