Patch Tuesday Archive
Patch Tuesday January 2025
Total CVEs
165
Critical
14
Important
150
Exploited
3
Publicly Disclosed
5
All CVEs this month 165
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2025-21411 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21413 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21210 | Windows BitLocker Information Disclosure Vulnerability | Important | 4.2 |
Windows Virtual Trusted Platform Module | - | - | - |
| CVE-2025-21214 | Windows BitLocker Information Disclosure Vulnerability | Important | 4.2 |
Windows BitLocker | - | - | - |
| CVE-2025-21215 | Secure Boot Security Feature Bypass Vulnerability | Important | 4.6 |
Windows Boot Manager | - | - | - |
| CVE-2025-21233 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21234 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7.8 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-21235 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7.8 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-21236 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21237 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21239 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21241 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21242 | Windows Kerberos Information Disclosure Vulnerability | Important | 5.9 |
Windows Kerberos | - | - | - |
| CVE-2025-21243 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21244 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21248 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21249 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21251 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21252 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21255 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21257 | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | Important | 5.5 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2025-21258 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21260 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21263 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21265 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21266 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21268 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21269 | Windows HTML Platforms Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21270 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21271 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2025-21272 | Windows COM Server Information Disclosure Vulnerability | Important | 6.5 |
Windows COM | - | - | - |
| CVE-2025-21277 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21280 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | Important | 5.5 |
Windows Virtual Trusted Platform Module | - | - | - |
| CVE-2025-21281 | Microsoft COM for Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Windows COM | - | - | - |
| CVE-2025-21282 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21284 | Windows Virtual Trusted Platform Module Denial of Service Vulnerability | Important | 5.5 |
Windows Virtual Trusted Platform Module | - | - | - |
| CVE-2025-21285 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21288 | Windows COM Server Information Disclosure Vulnerability | Important | 6.5 |
Windows COM | - | - | - |
| CVE-2025-21289 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21290 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21291 | Windows Direct Show Remote Code Execution Vulnerability | Important | 8.8 |
Windows Direct Show | - | - | - |
| CVE-2025-21293 | Active Directory Domain Services Elevation of Privilege Vulnerability | Important | 8.8 |
Active Directory Domain Services | - | - | - |
| CVE-2025-21294 | Microsoft Digest Authentication Remote Code Execution Vulnerability | Critical | 8.1 |
Microsoft Digest Authentication | - | - | - |
| CVE-2025-21295 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | Critical | 8.1 |
Windows SPNEGO Extended Negotiation | - | - | - |
| CVE-2025-21296 | BranchCache Remote Code Execution Vulnerability | Critical | 7.5 |
BranchCache | - | - | - |
| CVE-2025-21297 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-21298 | Windows OLE Remote Code Execution Vulnerability | Critical | 9.8 |
Windows OLE | - | - | - |
| CVE-2025-21299 | Windows Kerberos Security Feature Bypass Vulnerability | Important | 7.8 |
Windows Kerberos | - | - | - |
| CVE-2025-21301 | Windows Geolocation Service Information Disclosure Vulnerability | Important | 6.5 |
Windows Geolocation Service | - | - | - |
| CVE-2025-21302 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21303 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21304 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2025-21306 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21309 | Windows Remote Desktop Services Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-21314 | Windows SmartScreen Spoofing Vulnerability | Important | 6.5 |
Windows SmartScreen | - | - | - |
| CVE-2025-21315 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Brokering File System | - | - | Yes |
| CVE-2025-21316 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21318 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21319 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21320 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21321 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21327 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21176 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | Important | 8.8 |
.NET, .NET Framework, Visual Studio | - | - | - |
| CVE-2025-21178 | Visual Studio Remote Code Execution Vulnerability | Important | 8.8 |
Visual Studio | - | - | - |
| CVE-2025-21173 | .NET Elevation of Privilege Vulnerability | Important | 7.3 |
.NET | - | - | - |
| CVE-2025-21341 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21344 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2025-21345 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2025-21346 | Microsoft Office Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-21348 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2025-21354 | Microsoft Excel Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-21356 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2025-21357 | Microsoft Outlook Remote Code Execution Vulnerability | Important | 6.7 |
Microsoft Office Outlook | - | - | - |
| CVE-2025-21362 | Microsoft Excel Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office Excel | - | - | - |
| CVE-2025-21363 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2025-21364 | Microsoft Excel Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-21365 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-21366 | Microsoft Access Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Access | - | Yes | - |
| CVE-2025-21382 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2025-21219 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21389 | Windows upnphost.dll Denial of Service Vulnerability | Important | 7.5 |
Windows UPnP Device Host | - | - | - |
| CVE-2025-21393 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2025-21395 | Microsoft Access Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Access | - | Yes | - |
| CVE-2025-21403 | On-Premises Data Gateway Information Disclosure Vulnerability | Important | 6.4 |
Microsoft Azure Gateway Manager | - | - | - |
| CVE-2025-21217 | Windows NTLM Spoofing Vulnerability | Important | 6.5 |
Windows NTLM | - | - | - |
| CVE-2025-21405 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.3 |
Visual Studio | - | - | - |
| CVE-2025-21278 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Important | 5.5 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-21329 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21328 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21330 | Windows Remote Desktop Services Denial of Service Vulnerability | Important | 7.5 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-21220 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Hyper-V NT Kernel Integration VSP | Yes | - | - |
| CVE-2025-21415 | Azure AI Face Service Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure AI Face Service | - | - | - |
| CVE-2025-21193 | Active Directory Federation Server Spoofing Vulnerability | Important | 6.5 |
Active Directory Federation Services | - | - | - |
| CVE-2025-21207 | Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | Important | 7.5 |
Windows Connected Devices Platform Service | - | - | - |
| CVE-2025-21202 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | Important | 6.1 |
Windows Recovery Environment Agent | - | - | - |
| CVE-2025-21187 | Microsoft Power Automate Remote Code Execution Vulnerability | Important | 7.8 |
Power Automate | - | - | - |
| CVE-2025-21186 | Microsoft Access Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Access | - | Yes | - |
| CVE-2025-21211 | Secure Boot Security Feature Bypass Vulnerability | Important | 6.8 |
Windows Boot Loader | - | - | - |
| CVE-2025-21213 | Secure Boot Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-21224 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | Important | 8.1 |
Line Printer Daemon Service (LPD) | - | - | - |
| CVE-2025-21225 | Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | Important | 5.9 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-21226 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21227 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21228 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21229 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21230 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2025-21231 | IP Helper Denial of Service Vulnerability | Important | 7.5 |
IP Helper | - | - | - |
| CVE-2025-21232 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21256 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21261 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21189 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 4.3 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21273 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21274 | Windows Event Tracing Denial of Service Vulnerability | Important | 5.5 |
Windows Event Tracing | - | - | - |
| CVE-2025-21275 | Windows App Package Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | Yes | - |
| CVE-2025-21276 | Windows MapUrlToZone Denial of Service Vulnerability | Important | 7.5 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21286 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21287 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2025-21292 | Windows Search Service Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Windows Search Component | - | - | - |
| CVE-2025-21300 | Windows upnphost.dll Denial of Service Vulnerability | Important | 7.5 |
Windows UPnP Device Host | - | - | - |
| CVE-2025-21305 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21307 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Critical | 9.8 |
Reliable Multicast Transport Driver (RMCAST) | - | - | - |
| CVE-2025-21308 | Windows Themes Spoofing Vulnerability | Important | 6.5 |
Windows Themes | - | Yes | - |
| CVE-2025-21310 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21312 | Windows Smart Card Reader Information Disclosure Vulnerability | Important | 2.4 |
Windows Smart Card | - | - | - |
| CVE-2025-21317 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21323 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel Memory | - | - | - |
| CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2025-21324 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Digital Media | - | - | - |
| CVE-2025-21331 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Installer | - | - | - |
| CVE-2025-21336 | Windows Cryptographic Information Disclosure Vulnerability | Important | 5.6 |
Windows Cryptographic Services | - | - | - |
| CVE-2025-21338 | GDI+ Remote Code Execution Vulnerability | Important | 7.8 |
Windows Win32K - GRFX | - | - | - |
| CVE-2025-21339 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21340 | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Hello | - | - | - |
| CVE-2025-21343 | Windows Web Threat Defense User Service Information Disclosure Vulnerability | Important | 7.5 |
Windows Web Threat Defense User Service | - | - | - |
| CVE-2025-21361 | Microsoft Outlook Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Outlook for Mac | - | - | - |
| CVE-2025-21370 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2025-21372 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Brokering File System | - | - | Yes |
| CVE-2025-21374 | Windows CSC Service Information Disclosure Vulnerability | Important | 5.5 |
Windows Client-Side Caching (CSC) Service | - | - | - |
| CVE-2025-21378 | Windows CSC Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Client-Side Caching (CSC) Service | - | - | - |
| CVE-2025-21402 | Microsoft Office OneNote Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office OneNote | - | - | - |
| CVE-2025-21218 | Windows Kerberos Denial of Service Vulnerability | Important | 7.5 |
Windows Kerberos | - | - | - |
| CVE-2025-21380 | Azure Marketplace SaaS Resources Information Disclosure Vulnerability | Critical | 6.5 |
Azure Marketplace SaaS Resources | - | - | - |
| CVE-2025-21385 | Microsoft Purview Information Disclosure Vulnerability | Critical | 6.5 |
Microsoft Purview | - | - | - |
| CVE-2025-21313 | Windows Security Account Manager (SAM) Denial of Service Vulnerability | Important | 6.5 |
Windows Security Account Manager | - | - | - |
| CVE-2025-21332 | MapUrlToZone Security Feature Bypass Vulnerability | Important | 8.8 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-21326 | Internet Explorer Remote Code Execution Vulnerability | Important | 7.8 |
Internet Explorer | - | - | - |
| CVE-2025-21311 | Windows NTLM V1 Elevation of Privilege Vulnerability | Critical | 9.8 |
Windows NTLM | - | - | - |
| CVE-2025-21333 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Hyper-V NT Kernel Integration VSP | Yes | - | - |
| CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Hyper-V NT Kernel Integration VSP | Yes | - | - |
| CVE-2025-21325 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Secure Kernel Mode | - | - | - |
| CVE-2025-21185 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2025-21262 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 5.4 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2025-21246 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21417 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21250 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21240 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21238 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21223 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21409 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21245 | Windows Telephony Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Telephony Service | - | - | - |
| CVE-2025-21396 | Microsoft Account Elevation of Privilege Vulnerability | Critical | 8.2 |
Microsoft Account | - | - | - |
| CVE-2025-21171 | .NET Remote Code Execution Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2025-21360 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft AutoUpdate (MAU) | - | - | - |
| CVE-2025-21399 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | Important | 7.4 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 58 | 9 |
| Elevation of Privilege | 45 | 3 |
| Information Disclosure | 22 | 2 |
| Denial of Service | 20 | - |
| Security Feature Bypass | 14 | - |
| Spoofing | 6 | - |
Affected Products 70
| Product | CVEs | Exploited |
|---|---|---|
| Windows Telephony Service | 28 | - |
| Windows Digital Media | 17 | - |
| Windows MapUrlToZone | 8 | - |
| Windows Message Queuing | 8 | - |
| Windows Kernel Memory | 7 | - |
| Windows Remote Desktop Services | 5 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| Microsoft Office Access | 3 | - |
| Microsoft Office Excel | 3 | - |
| Microsoft Office SharePoint | 3 | - |
| Windows COM | 3 | - |
| Windows Hyper-V NT Kernel Integration VSP | 3 | 3 |
| Windows Installer | 3 | - |
| Windows Kerberos | 3 | - |
| Windows Virtual Trusted Platform Module | 3 | - |
| .NET | 2 | - |
| Microsoft Brokering File System | 2 | - |
| Microsoft Office | 2 | - |
| Microsoft Office Visio | 2 | - |
| Visual Studio | 2 | - |
| Windows BitLocker | 2 | - |
| Windows Client-Side Caching (CSC) Service | 2 | - |
| Windows NTLM | 2 | - |
| Windows PrintWorkflowUserSvc | 2 | - |
| Windows UPnP Device Host | 2 | - |
| .NET and Visual Studio | 1 | - |
| .NET, .NET Framework, Visual Studio | 1 | - |
| Active Directory Domain Services | 1 | - |
| Active Directory Federation Services | 1 | - |
| Azure AI Face Service | 1 | - |
| Azure Marketplace SaaS Resources | 1 | - |
| BranchCache | 1 | - |
| IP Helper | 1 | - |
| Internet Explorer | 1 | - |
| Line Printer Daemon Service (LPD) | 1 | - |
| Microsoft Account | 1 | - |
| Microsoft AutoUpdate (MAU) | 1 | - |
| Microsoft Azure Gateway Manager | 1 | - |
| Microsoft Digest Authentication | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft Office OneNote | 1 | - |
| Microsoft Office Outlook | 1 | - |
| Microsoft Office Outlook for Mac | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Purview | 1 | - |
| Microsoft Windows Search Component | 1 | - |
| Power Automate | 1 | - |
| Reliable Multicast Transport Driver (RMCAST) | 1 | - |
| Windows Boot Loader | 1 | - |
| Windows Boot Manager | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Connected Devices Platform Service | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows DWM Core Library | 1 | - |
| Windows Direct Show | 1 | - |
| Windows Event Tracing | 1 | - |
| Windows Geolocation Service | 1 | - |
| Windows Hello | 1 | - |
| Windows OLE | 1 | - |
| Windows Recovery Environment Agent | 1 | - |
| Windows SPNEGO Extended Negotiation | 1 | - |
| Windows Secure Kernel Mode | 1 | - |
| Windows Security Account Manager | 1 | - |
| Windows Smart Card | 1 | - |
| Windows SmartScreen | 1 | - |
| Windows Themes | 1 | - |
| Windows Virtualization-Based Security (VBS) Enclave | 1 | - |
| Windows WLAN Auto Config Service | 1 | - |
| Windows Web Threat Defense User Service | 1 | - |
| Windows Win32K - GRFX | 1 | - |