Microsoft Windows Server 2025 vulnerabilities
1,706 known vulnerabilities affecting microsoft/windows_server_2025.
Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
47
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9
Vulnerabilities
Page 83 of 86
CVE-2025-55337P4MEDIUMCVSS 4.6fixed in 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-55337 [MEDIUM] CWE-841 CVE-2025-55337: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-55682P4MEDIUMCVSS 4.6fixed in 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-55682 [MEDIUM] CWE-841 CVE-2025-55682: Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-26175P4MEDIUMCVSS 4.6fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-26175 [MEDIUM] CWE-908 CVE-2026-26175: Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a se
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-20825P4MEDIUMCVSS 4.4fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20825 [MEDIUM] CWE-284 CVE-2026-20825: Improper access control in Windows Hyper-V allows an authorized attacker to disclose information loc
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21254P4MEDIUMCVSS 6.5fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21254 [MEDIUM] CWE-125 CVE-2025-21254: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21352P4MEDIUMCVSS 6.5fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21212P4MEDIUMCVSS 6.5fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21212 [MEDIUM] CWE-125 CVE-2025-21212: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21216P4MEDIUMCVSS 6.5fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21216 [MEDIUM] CWE-125 CVE-2025-21216: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2025-21336P4MEDIUMCVSS 5.6fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21336 [MEDIUM] CWE-203 CVE-2025-21336: Windows Cryptographic Information Disclosure Vulnerability
Windows Cryptographic Information Disclosure Vulnerability
nvd
CVE-2025-21257P4MEDIUMCVSS 5.5fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21257 [MEDIUM] CWE-125 CVE-2025-21257: Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2026-45606P4MEDIUMCVSS 5.5fixed in 10.0.26100.32995≥ 10.0.26100.0, < 10.0.26100.329952026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2026-50684P4MEDIUMCVSS 4.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50684 [MEDIUM] CWE-79 CVE-2026-50684: Improper neutralization of input during web page generation ('cross-site scripting') in Active Direc
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2025-48813P4MEDIUMCVSS 4.7≤ 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-48813 [MEDIUM] CWE-324 CVE-2025-48813: Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perfor
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
nvd
CVE-2026-20962P4MEDIUMCVSS 4.4fixed in 10.0.26100.32230≥ 10.0.26100.0, < 10.0.26100.322302026-01-13
CVE-2026-20962 [MEDIUM] CWE-908 CVE-2026-20962: Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized a
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32220P4MEDIUMCVSS 4.4fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-32220 [MEDIUM] CWE-284 CVE-2026-32220: Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32209P4MEDIUMCVSS 4.4fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-32209 [MEDIUM] CWE-284 CVE-2026-32209: Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-21347P4MEDIUMCVSS 6.0fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2025-21374P4MEDIUMCVSS 5.5fixed in 10.0.26100.2894≥ 10.0.26100.0, < 10.0.26100.28942025-01-14
CVE-2025-21374 [MEDIUM] CWE-125 CVE-2025-21374: Windows CSC Service Information Disclosure Vulnerability
Windows CSC Service Information Disclosure Vulnerability
nvd
CVE-2026-20928P4MEDIUMCVSS 4.6fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-20928 [MEDIUM] CWE-212 CVE-2026-20928: Improper removal of sensitive information before storage or transfer in Windows Recovery Environment
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-59198P4MEDIUMCVSS 5.0fixed in 10.0.26100.6899≥ 10.0.26100.0, < 10.0.26100.68992025-10-14
CVE-2025-59198 [MEDIUM] CWE-20 CVE-2025-59198: Improper input validation in Microsoft Windows Search Component allows an authorized attacker to den
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
nvd