Msrc Windows Server 2025 vulnerabilities
604 known vulnerabilities affecting msrc/windows_server_2025.
Total CVEs
604
CISA KEV
14
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH401MEDIUM192LOW4
Vulnerabilities
Page 6 of 31
CVE-2025-62469HIGHCVSS 7.02025-12-09
CVE-2025-62469 [HIGH] CWE-362 Microsoft Brokering File System Elevation of Privilege Vulnerability
Microsoft Brokering File System Elevation of Privilege Vulnerability
Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful e
msrc
CVE-2025-62456HIGHCVSS 8.82025-12-09
CVE-2025-62456 [HIGH] CWE-122 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
An authenticated attacker with access to a shared folder on a system using a Resilient File System (ReFS) volume could exploi
msrc
CVE-2025-62474HIGHCVSS 7.82025-12-09
CVE-2025-62474 [HIGH] CWE-284 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Description: Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SY
msrc
CVE-2025-62461HIGHCVSS 7.82025-12-09
CVE-2025-62461 [HIGH] CWE-126 Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Description: Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows
msrc
CVE-2025-62221HIGHCVSS 7.8KEV2025-12-09
CVE-2025-62221 [HIGH] CWE-416 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Description: Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges
msrc
CVE-2025-64680HIGHCVSS 7.82025-12-09
CVE-2025-64680 [HIGH] CWE-122 Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows DWM Core Library: W
msrc
CVE-2025-62573HIGHCVSS 7.02025-12-09
CVE-2025-62573 [HIGH] CWE-416 DirectX Graphics Kernel Elevation of Privilege Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Description: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: What privileges could b
msrc
CVE-2025-59516HIGHCVSS 7.82025-12-09
CVE-2025-59516 [HIGH] CWE-306 Windows Storage VSP Driver Elevation of Privilege Vulnerability
Windows Storage VSP Driver Elevation of Privilege Vulnerability
Description: Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Win
msrc
CVE-2025-62565HIGHCVSS 7.32025-12-09
CVE-2025-62565 [HIGH] CWE-416 Windows File Explorer Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
Description: Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, user interaction is r
msrc
CVE-2025-62464HIGHCVSS 7.82025-12-09
CVE-2025-62464 [HIGH] CWE-126 Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Description: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Projected File
msrc
CVE-2025-64679HIGHCVSS 7.82025-12-09
CVE-2025-64679 [HIGH] CWE-122 Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows DWM Core Library: W
msrc
CVE-2025-64661HIGHCVSS 7.82025-12-09
CVE-2025-64661 [HIGH] CWE-362 Windows Shell Elevation of Privilege Vulnerability
Windows Shell Elevation of Privilege Vulnerability
Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker
msrc
CVE-2025-62467HIGHCVSS 7.82025-12-09
CVE-2025-62467 [HIGH] CWE-190 Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Description: Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows
msrc
CVE-2025-62570HIGHCVSS 7.12025-12-09
CVE-2025-62570 [HIGH] CWE-284 Windows Camera Frame Server Monitor Information Disclosure Vulnerability
Windows Camera Frame Server Monitor Information Disclosure Vulnerability
Description: Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain kernel memory content.
Windows Camera Fram
msrc
CVE-2025-62457HIGHCVSS 7.82025-12-09
CVE-2025-62457 [HIGH] CWE-125 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Description: Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privil
msrc
CVE-2025-62462HIGHCVSS 7.82025-12-09
CVE-2025-62462 [HIGH] CWE-126 Windows Projected File System Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Description: Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Projected File
msrc
CVE-2025-62454HIGHCVSS 7.82025-12-09
CVE-2025-62454 [HIGH] CWE-122 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Description: Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTE
msrc
CVE-2025-62463MEDIUMCVSS 6.52025-12-09
CVE-2025-62463 [MEDIUM] CWE-476 DirectX Graphics Kernel Denial of Service Vulnerability
DirectX Graphics Kernel Denial of Service Vulnerability
Description: Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker
msrc
CVE-2025-62567MEDIUMCVSS 5.32025-12-09
CVE-2025-62567 [MEDIUM] CWE-191 Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Description: Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and
msrc
CVE-2025-64670MEDIUMCVSS 6.52025-12-09
CVE-2025-64670 [MEDIUM] CWE-200 Windows DirectX Information Disclosure Vulnerability
Windows DirectX Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain memory address within kernel space. Knowing th
msrc