Msrc Windows Server 2025 vulnerabilities

604 known vulnerabilities affecting msrc/windows_server_2025.

Total CVEs
604
CISA KEV
14
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH401MEDIUM192LOW4

Vulnerabilities

Page 23 of 31
CVE-2025-26680HIGHCVSS 7.52025-04-08
CVE-2025-26680 [HIGH] CWE-400 Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability Description: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. Windows Standards-Based Storage Management Service: Windows Standards-Based Storage Management Service Microsoft: Microsoft Customer Ac
msrc
CVE-2025-27739HIGHCVSS 7.82025-04-08
CVE-2025-27739 [HIGH] CWE-822 Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability Description: Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. FAQ: What privileges could an attacker gain? An authenticated attacker could elevate privileges to Secure Kernel. FAQ: How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker would first have to log on to
msrc
CVE-2025-29812HIGHCVSS 7.82025-04-08
CVE-2025-29812 [HIGH] CWE-822 DirectX Graphics Kernel Elevation of Privilege Vulnerability DirectX Graphics Kernel Elevation of Privilege Vulnerability Description: Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows Kernel Memory: Window
msrc
CVE-2025-24074HIGHCVSS 7.82025-04-08
CVE-2025-24074 [HIGH] CWE-20 Microsoft DWM Core Library Elevation of Privilege Vulnerability Microsoft DWM Core Library Elevation of Privilege Vulnerability Description: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows DWM Core Library:
msrc
CVE-2025-27479HIGHCVSS 7.52025-04-08
CVE-2025-27479 [HIGH] CWE-410 Kerberos Key Distribution Proxy Service Denial of Service Vulnerability Kerberos Key Distribution Proxy Service Denial of Service Vulnerability Description: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. Windows Kerberos: Windows Kerberos Microsoft: Microsoft Customer Action Required: Yes Impact: Denial of Service Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitat
msrc
CVE-2025-27480HIGHCVSS 8.12025-04-08
CVE-2025-27480 [HIGH] CWE-416 Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability Description: Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. FAQ: How could an attacker exploit this vulnerability? An attacker could successfully exploit this vulnerability by attempting to connect to a system with the Remote Desktop Gateway role, triggering the rac
msrc
CVE-2025-27490HIGHCVSS 7.82025-04-08
CVE-2025-27490 [HIGH] CWE-122 Windows Bluetooth Service Elevation of Privilege Vulnerability Windows Bluetooth Service Elevation of Privilege Vulnerability Description: Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could create or delete files in the security context of
msrc
CVE-2025-27485HIGHCVSS 7.52025-04-08
CVE-2025-27485 [HIGH] CWE-400 Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability Description: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. Windows Standards-Based Storage Management Service: Windows Standards-Based Storage Management Service Microsoft: Microsoft Customer Ac
msrc
CVE-2025-27476HIGHCVSS 7.82025-04-08
CVE-2025-27476 [HIGH] CWE-416 Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability Description: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows Digital Media: Windows Digital Media Mi
msrc
CVE-2025-27486HIGHCVSS 7.52025-04-08
CVE-2025-27486 [HIGH] CWE-400 Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability Description: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. Windows Standards-Based Storage Management Service: Windows Standards-Based Storage Management Service Microsoft: Microsoft Customer Ac
msrc
CVE-2025-27492HIGHCVSS 7.02025-04-08
CVE-2025-27492 [HIGH] CWE-362 Windows Secure Channel Elevation of Privilege Vulnerability Windows Secure Channel Elevation of Privilege Vulnerability Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnera
msrc
CVE-2025-27729HIGHCVSS 7.82025-04-08
CVE-2025-27729 [HIGH] CWE-416 Windows Shell Remote Code Execution Vulnerability Windows Shell Remote Code Execution Vulnerability Description: Use after free in Windows Shell allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrar
msrc
CVE-2025-27738MEDIUMCVSS 6.52025-04-08
CVE-2025-27738 [MEDIUM] CWE-284 Windows Resilient File System (ReFS) Information Disclosure Vulnerability Windows Resilient File System (ReFS) Information Disclosure Vulnerability Description: Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerab
msrc
CVE-2025-26667MEDIUMCVSS 6.52025-04-08
CVE-2025-26667 [MEDIUM] CWE-200 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Description: Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. FAQ: What type of information could be disclosed by this vulnerability? An attacker who successful
msrc
CVE-2025-26681MEDIUMCVSS 6.72025-04-08
CVE-2025-26681 [MEDIUM] CWE-416 Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Description: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: What privileges could be gained by an attacker wh
msrc
CVE-2025-26644MEDIUMCVSS 5.12025-04-08
CVE-2025-26644 [MEDIUM] CWE-1039 Windows Hello Spoofing Vulnerability Windows Hello Spoofing Vulnerability Description: Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. Windows Hello: Windows Hello Microsoft: Microsoft Customer Action Required: Yes Impact: Spoofing Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less L
msrc
CVE-2025-26676MEDIUMCVSS 6.52025-04-08
CVE-2025-26676 [MEDIUM] CWE-126 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. FAQ: What type of information could be disclosed by this vulnerability? An attacker who successfully exploited this vulnerability could pote
msrc
CVE-2025-27736MEDIUMCVSS 5.52025-04-08
CVE-2025-27736 [MEDIUM] CWE-200 Windows Power Dependency Coordinator Information Disclosure Vulnerability Windows Power Dependency Coordinator Information Disclosure Vulnerability Description: Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. FAQ: What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of certain mem
msrc
CVE-2025-26637MEDIUMCVSS 6.82025-04-08
CVE-2025-26637 [MEDIUM] CWE-693 Windows BitLocker Security Feature Bypass Vulnerability Windows BitLocker Security Feature Bypass Vulnerability Description: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. FAQ: Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available? Yes. As of April 9, 2025, the security update (5055547) for Windows 10 for x64-based Systems
msrc
CVE-2025-27474MEDIUMCVSS 6.52025-04-08
CVE-2025-27474 [MEDIUM] CWE-908 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. FAQ: What type of information could be disclosed by this vulnerability? An attacker who successfully exploited this vulnerabili
msrc