Msrc Windows Server 2025 vulnerabilities
604 known vulnerabilities affecting msrc/windows_server_2025.
Total CVEs
604
CISA KEV
14
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH401MEDIUM192LOW4
Vulnerabilities
Page 23 of 31
CVE-2025-26680HIGHCVSS 7.52025-04-08
CVE-2025-26680 [HIGH] CWE-400 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Windows Standards-Based Storage Management Service: Windows Standards-Based Storage Management Service
Microsoft: Microsoft
Customer Ac
msrc
CVE-2025-27739HIGHCVSS 7.82025-04-08
CVE-2025-27739 [HIGH] CWE-822 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Description: Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could an attacker gain?
An authenticated attacker could elevate privileges to Secure Kernel.
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, an attacker would first have to log on to
msrc
CVE-2025-29812HIGHCVSS 7.82025-04-08
CVE-2025-29812 [HIGH] CWE-822 DirectX Graphics Kernel Elevation of Privilege Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Description: Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Kernel Memory: Window
msrc
CVE-2025-24074HIGHCVSS 7.82025-04-08
CVE-2025-24074 [HIGH] CWE-20 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Microsoft DWM Core Library Elevation of Privilege Vulnerability
Description: Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows DWM Core Library:
msrc
CVE-2025-27479HIGHCVSS 7.52025-04-08
CVE-2025-27479 [HIGH] CWE-410 Kerberos Key Distribution Proxy Service Denial of Service Vulnerability
Kerberos Key Distribution Proxy Service Denial of Service Vulnerability
Description: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
Windows Kerberos: Windows Kerberos
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitat
msrc
CVE-2025-27480HIGHCVSS 8.12025-04-08
CVE-2025-27480 [HIGH] CWE-416 Windows Remote Desktop Services Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
Description: Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
An attacker could successfully exploit this vulnerability by attempting to connect to a system with the Remote Desktop Gateway role, triggering the rac
msrc
CVE-2025-27490HIGHCVSS 7.82025-04-08
CVE-2025-27490 [HIGH] CWE-122 Windows Bluetooth Service Elevation of Privilege Vulnerability
Windows Bluetooth Service Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could create or delete files in the security context of
msrc
CVE-2025-27485HIGHCVSS 7.52025-04-08
CVE-2025-27485 [HIGH] CWE-400 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Windows Standards-Based Storage Management Service: Windows Standards-Based Storage Management Service
Microsoft: Microsoft
Customer Ac
msrc
CVE-2025-27476HIGHCVSS 7.82025-04-08
CVE-2025-27476 [HIGH] CWE-416 Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
Description: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Digital Media: Windows Digital Media
Mi
msrc
CVE-2025-27486HIGHCVSS 7.52025-04-08
CVE-2025-27486 [HIGH] CWE-400 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Description: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Windows Standards-Based Storage Management Service: Windows Standards-Based Storage Management Service
Microsoft: Microsoft
Customer Ac
msrc
CVE-2025-27492HIGHCVSS 7.02025-04-08
CVE-2025-27492 [HIGH] CWE-362 Windows Secure Channel Elevation of Privilege Vulnerability
Windows Secure Channel Elevation of Privilege Vulnerability
Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnera
msrc
CVE-2025-27729HIGHCVSS 7.82025-04-08
CVE-2025-27729 [HIGH] CWE-416 Windows Shell Remote Code Execution Vulnerability
Windows Shell Remote Code Execution Vulnerability
Description: Use after free in Windows Shell allows an unauthorized attacker to execute code locally.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrar
msrc
CVE-2025-27738MEDIUMCVSS 6.52025-04-08
CVE-2025-27738 [MEDIUM] CWE-284 Windows Resilient File System (ReFS) Information Disclosure Vulnerability
Windows Resilient File System (ReFS) Information Disclosure Vulnerability
Description: Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerab
msrc
CVE-2025-26667MEDIUMCVSS 6.52025-04-08
CVE-2025-26667 [MEDIUM] CWE-200 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successful
msrc
CVE-2025-26681MEDIUMCVSS 6.72025-04-08
CVE-2025-26681 [MEDIUM] CWE-416 Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: What privileges could be gained by an attacker wh
msrc
CVE-2025-26644MEDIUMCVSS 5.12025-04-08
CVE-2025-26644 [MEDIUM] CWE-1039 Windows Hello Spoofing Vulnerability
Windows Hello Spoofing Vulnerability
Description: Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
Windows Hello: Windows Hello
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less L
msrc
CVE-2025-26676MEDIUMCVSS 6.52025-04-08
CVE-2025-26676 [MEDIUM] CWE-126 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could pote
msrc
CVE-2025-27736MEDIUMCVSS 5.52025-04-08
CVE-2025-27736 [MEDIUM] CWE-200 Windows Power Dependency Coordinator Information Disclosure Vulnerability
Windows Power Dependency Coordinator Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain mem
msrc
CVE-2025-26637MEDIUMCVSS 6.82025-04-08
CVE-2025-26637 [MEDIUM] CWE-693 Windows BitLocker Security Feature Bypass Vulnerability
Windows BitLocker Security Feature Bypass Vulnerability
Description: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
FAQ: Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available?
Yes. As of April 9, 2025, the security update (5055547) for Windows 10 for x64-based Systems
msrc
CVE-2025-27474MEDIUMCVSS 6.52025-04-08
CVE-2025-27474 [MEDIUM] CWE-908 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerabili
msrc