Microsoft Windows Server 2025 vulnerabilities
1,706 known vulnerabilities affecting microsoft/windows_server_2025.
Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
46
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9
Vulnerabilities
Page 56 of 86
CVE-2026-20826P3HIGHCVSS 7.0fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20826 [HIGH] CWE-362 CVE-2026-20826: Concurrent execution using shared resource with improper synchronization ('race condition') in Table
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34342P3HIGHCVSS 7.0fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-34342 [HIGH] CWE-362 CVE-2026-34342: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20836P3HIGHCVSS 7.0fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20836 [HIGH] CWE-362 CVE-2026-20836: Concurrent execution using shared resource with improper synchronization ('race condition') in Graph
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20830P3HIGHCVSS 7.0fixed in 10.0.26100.7623≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20830 [HIGH] CWE-362 CVE-2026-20830: Concurrent execution using shared resource with improper synchronization ('race condition') in Capab
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25178P3HIGHCVSS 7.0fixed in 10.0.26100.32463≥ 10.0.26100.0, < 10.0.26100.325222026-03-10
CVE-2026-25178 [HIGH] CWE-416 CVE-2026-25178: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49762P3HIGHCVSS 7.0fixed in 10.0.26100.4851≥ 10.0.26100.0, < 10.0.26100.49462025-08-12
CVE-2025-49762 [HIGH] CWE-362 CVE-2025-49762: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21237P3HIGHCVSS 7.0fixed in 10.0.26100.32313≥ 10.0.26100.0, < 10.0.26100.323702026-02-10
CVE-2026-21237 [HIGH] CWE-362 CVE-2026-21237: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21234P3HIGHCVSS 7.0fixed in 10.0.26100.32313≥ 10.0.26100.0, < 10.0.26100.323702026-02-10
CVE-2026-21234 [HIGH] CWE-362 CVE-2026-21234: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26165P3HIGHCVSS 7.0fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-26165 [HIGH] CWE-416 CVE-2026-26165: Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55335P3HIGHCVSS 7.0fixed in 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-55335 [HIGH] CWE-362 CVE-2025-55335: Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-62217P3HIGHCVSS 7.0fixed in 10.0.26100.7092≥ 10.0.26100.0, < 10.0.26100.71712025-11-11
CVE-2025-62217 [HIGH] CWE-362 CVE-2025-62217: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40410P3HIGHCVSS 7.0fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-40410 [HIGH] CWE-416 CVE-2026-40410: Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59507P3HIGHCVSS 7.0fixed in 10.0.26100.7092≥ 10.0.26100.0, < 10.0.26100.71712025-11-11
CVE-2025-59507 [HIGH] CWE-362 CVE-2025-59507: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59508P3HIGHCVSS 7.0fixed in 10.0.26100.7092≥ 10.0.26100.0, < 10.0.26100.71712025-11-11
CVE-2025-59508 [HIGH] CWE-362 CVE-2025-59508: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59506P3HIGHCVSS 7.0fixed in 10.0.26100.7092≥ 10.0.26100.0, < 10.0.26100.71712025-11-11
CVE-2025-59506 [HIGH] CWE-362 CVE-2025-59506: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62573P3HIGHCVSS 7.0fixed in 10.0.26100.7392≥ 10.0.26100.0, < 10.0.26100.74622025-12-09
CVE-2025-62573 [HIGH] CWE-362 CVE-2025-62573: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42911P3HIGHCVSS 7.0fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-42911 [HIGH] CWE-416 CVE-2026-42911: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34335P3HIGHCVSS 7.0fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-34335 [HIGH] CWE-416 CVE-2026-34335: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58637P3HIGHCVSS 7.0fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-58637 [HIGH] CWE-416 CVE-2026-58637: Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58544P3HIGHCVSS 7.0fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-58544 [HIGH] CWE-416 CVE-2026-58544: Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
nvd