Total CVEs

111

Critical

17

Important

91

Exploited

0

Publicly Disclosed

1

All CVEs this month 111

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2025-49751 Windows Hyper-V Denial of Service Vulnerability Important 6.8 Role: Windows Hyper-V - - -
CVE-2025-49745 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Important 5.4 Microsoft Dynamics 365 (on-premises) - - -
CVE-2025-49758 Microsoft SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2025-53727 Microsoft SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2025-33051 Microsoft Exchange Server Information Disclosure Vulnerability Important 7.5 Microsoft Exchange Server - - -
CVE-2025-53730 Microsoft Office Visio Remote Code Execution Vulnerability Important 7.8 Microsoft Office Visio - - -
CVE-2025-53741 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2025-53759 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2025-53760 Microsoft SharePoint Elevation of Privilege Vulnerability Important 7.1 Microsoft Office SharePoint - - -
CVE-2025-53761 Microsoft PowerPoint Remote Code Execution Vulnerability Important 7.8 Microsoft Office PowerPoint - - -
CVE-2025-24999 Microsoft SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2025-53772 Web Deploy Remote Code Execution Vulnerability Important 8.8 Web Deploy - - -
CVE-2025-53773 GitHub Copilot and Visual Studio Remote Code Execution Vulnerability Important 7.8 GitHub Copilot and Visual Studio - - -
CVE-2025-53781 Azure Virtual Machines Information Disclosure Vulnerability Critical 6.5 Azure Virtual Machines - - -
CVE-2025-53786 Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability Important 8 Microsoft Exchange Server - - -
CVE-2025-25005 Microsoft Exchange Server Tampering Vulnerability Important 6.5 Microsoft Exchange Server - - -
CVE-2025-25006 Microsoft Exchange Server Spoofing Vulnerability Important 5.3 Microsoft Exchange Server - - -
CVE-2025-25007 Microsoft Exchange Server Spoofing Vulnerability Important 5.3 Microsoft Exchange Server - - -
CVE-2025-49743 Windows Graphics Component Elevation of Privilege Vulnerability Important 6.7 Microsoft Graphics Component - - -
CVE-2025-49757 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49759 Microsoft SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2025-49761 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2025-49762 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-50153 Desktop Windows Manager Elevation of Privilege Vulnerability Important 7.8 Desktop Windows Manager - - -
CVE-2025-50154 Microsoft Windows File Explorer Spoofing Vulnerability Important 6.5 Windows File Explorer - - -
CVE-2025-50156 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 5.7 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-50158 Windows NTFS Information Disclosure Vulnerability Important 7 Windows NTFS - - -
CVE-2025-50159 Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability Important 7.3 Remote Access Point-to-Point Protocol (PPP) EAP-TLS - - -
CVE-2025-50160 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-50161 Win32k Elevation of Privilege Vulnerability Important 7.3 Windows Win32K - GRFX - - -
CVE-2025-50162 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-50163 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-50164 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-50165 Windows Graphics Component Remote Code Execution Vulnerability Critical 9.8 Microsoft Graphics Component - - Yes
CVE-2025-50166 Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability Important 6.5 Windows Distributed Transaction Coordinator - - -
CVE-2025-50167 Windows Hyper-V Elevation of Privilege Vulnerability Important 7 Role: Windows Hyper-V - - -
CVE-2025-50168 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - ICOMP - - -
CVE-2025-50169 Windows SMB Remote Code Execution Vulnerability Important 7.5 Windows SMB - - -
CVE-2025-50170 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important 7.8 Windows Cloud Files Mini Filter Driver - - Yes
CVE-2025-50171 Remote Desktop Spoofing Vulnerability Important 9.1 Remote Desktop Server - - -
CVE-2025-50172 DirectX Graphics Kernel Denial of Service Vulnerability Important 6.5 Windows DirectX - - -
CVE-2025-50173 Windows Installer Elevation of Privilege Vulnerability Important 7.8 Windows Installer - - -
CVE-2025-50176 DirectX Graphics Kernel Remote Code Execution Vulnerability Critical 7.8 Graphics Kernel - - -
CVE-2025-50177 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Critical 8.1 Windows Message Queuing - - -
CVE-2025-53131 Windows Media Remote Code Execution Vulnerability Important 8.8 Windows Media - - -
CVE-2025-53132 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - GRFX - - -
CVE-2025-53133 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability Important 7.8 Windows PrintWorkflowUserSvc - - -
CVE-2025-53134 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-53135 DirectX Graphics Kernel Elevation of Privilege Vulnerability Important 7 Windows DirectX - - -
CVE-2025-53136 NT OS Kernel Information Disclosure Vulnerability Important 5.5 Windows NT OS Kernel - - -
CVE-2025-53137 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-53138 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 5.7 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-53140 Windows Kernel Transaction Manager Elevation of Privilege Vulnerability Important 7 Kernel Transaction Manager - - -
CVE-2025-53141 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-53142 Microsoft Brokering File System Elevation of Privilege Vulnerability Important 7 Microsoft Brokering File System - - -
CVE-2025-53143 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Important 8.8 Windows Message Queuing - - -
CVE-2025-53144 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Important 8.8 Windows Message Queuing - - -
CVE-2025-53145 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Important 8.8 Windows Message Queuing - - -
CVE-2025-53147 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-53148 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 5.7 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-53149 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Important 7.8 Kernel Streaming WOW Thunk Service Driver - - -
CVE-2025-53151 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2025-53152 Desktop Windows Manager Remote Code Execution Vulnerability Important 7.8 Desktop Windows Manager - - -
CVE-2025-53153 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 5.7 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-53154 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-53155 Windows Hyper-V Elevation of Privilege Vulnerability Important 7.8 Role: Windows Hyper-V - - -
CVE-2025-53156 Windows Storage Port Driver Information Disclosure Vulnerability Important 5.5 Storage Port Driver - - -
CVE-2025-53716 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability Important 6.5 Windows Local Security Authority Subsystem Service (LSASS) - - -
CVE-2025-53718 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-53719 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 5.7 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-53720 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-53721 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability Important 7 Windows Connected Devices Platform Service - - -
CVE-2025-53722 Windows Remote Desktop Services Denial of Service Vulnerability Important 7.5 Windows Remote Desktop Services - - -
CVE-2025-53723 Windows Hyper-V Elevation of Privilege Vulnerability Important 7.8 Role: Windows Hyper-V - - -
CVE-2025-53724 Windows Push Notifications Apps Elevation of Privilege Vulnerability Important 7.8 Windows Push Notifications - - -
CVE-2025-53725 Windows Push Notifications Apps Elevation of Privilege Vulnerability Important 7.8 Windows Push Notifications - - -
CVE-2025-53726 Windows Push Notifications Apps Elevation of Privilege Vulnerability Important 7.8 Windows Push Notifications - - -
CVE-2025-53728 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Important 6.5 Microsoft Dynamics 365 (on-premises) - - -
CVE-2025-47954 Microsoft SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2025-53731 Microsoft Office Remote Code Execution Vulnerability Critical 8.4 Microsoft Office - - -
CVE-2025-53732 Microsoft Office Remote Code Execution Vulnerability Important 7.8 Microsoft Office - - -
CVE-2025-53733 Microsoft Word Remote Code Execution Vulnerability Critical 8.4 Microsoft Office Word - - -
CVE-2025-53734 Microsoft Office Visio Remote Code Execution Vulnerability Important 7.8 Microsoft Office Visio - - -
CVE-2025-53735 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2025-53736 Microsoft Word Information Disclosure Vulnerability Important 6.2 Microsoft Office Word - - -
CVE-2025-53737 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2025-53738 Microsoft Word Remote Code Execution Vulnerability Important 7.8 Microsoft Office Word - - -
CVE-2025-53739 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2025-53740 Microsoft Office Remote Code Execution Vulnerability Critical 8.4 Microsoft Office - - -
CVE-2025-53765 Azure Stack Hub Information Disclosure Vulnerability Important 5.5 Azure Stack - - -
CVE-2025-53766 GDI+ Remote Code Execution Vulnerability Critical 9.8 Windows GDI+ - - -
CVE-2025-53769 Windows Security App Spoofing Vulnerability Important 5.5 Windows Security App - - -
CVE-2025-50157 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 5.7 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-50155 Windows Push Notifications Apps Elevation of Privilege Vulnerability Important 7.8 Windows Push Notifications - - -
CVE-2025-53778 Windows NTLM Elevation of Privilege Vulnerability Critical 8.8 Windows NTLM - - -
CVE-2025-53779 Windows Kerberos Elevation of Privilege Vulnerability Moderate 7.2 Windows Kerberos - Yes -
CVE-2025-53783 Microsoft Teams Remote Code Execution Vulnerability Important 7.5 Microsoft Teams - - -
CVE-2025-53784 Microsoft Word Remote Code Execution Vulnerability Critical 8.4 Microsoft Office Word - - -
CVE-2025-53788 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability Important 7 Windows Subsystem for Linux - - -
CVE-2025-53789 Windows StateRepository API Server file Elevation of Privilege Vulnerability Important 7.8 Windows StateRepository API - - -
CVE-2025-53793 Azure Stack Hub Information Disclosure Vulnerability Critical 7.5 Azure Stack - - -
CVE-2025-48807 Windows Hyper-V Remote Code Execution Vulnerability Critical 6.7 Role: Windows Hyper-V - - -
CVE-2025-53792 Azure Portal Elevation of Privilege Vulnerability Critical 9.1 Azure Portal - - -
CVE-2025-53767 Azure OpenAI Elevation of Privilege Vulnerability Critical 10 Azure OpenAI - - -
CVE-2025-53774 Microsoft 365 Copilot BizChat Information Disclosure Vulnerability Critical 7.5 Microsoft 365 Copilot's Business Chat - - -
CVE-2025-53787 Microsoft 365 Copilot BizChat Information Disclosure Vulnerability Critical 7.5 Microsoft 365 Copilot's Business Chat - - -
CVE-2025-49755 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability Low 4.3 Microsoft Edge for Android - - -
CVE-2025-49707 Azure Virtual Machines Spoofing Vulnerability Critical 5.5 Azure Virtual Machines - - -
CVE-2025-49712 Microsoft SharePoint Remote Code Execution Vulnerability Important 8.8 Microsoft Office SharePoint - - -
CVE-2025-49736 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability Moderate 4.3 Microsoft Edge for Android - - -
CVE-2025-53729 Microsoft Azure File Sync Elevation of Privilege Vulnerability Important 7.8 Azure File Sync - - -

Threat Categories 6

Threat Category CVEs Critical
Elevation of Privilege 44 3
Remote Code Execution 35 9
Information Disclosure 18 4
Spoofing 9 1
Denial of Service 4 -
Tampering 1 -

Affected Products 55

Product CVEs Exploited
Windows Routing and Remote Access Service (RRAS) 12 -
Windows Ancillary Function Driver for WinSock 7 -
Microsoft Exchange Server 5 -
Microsoft Office Excel 5 -
Role: Windows Hyper-V 5 -
SQL Server 5 -
Microsoft Office Word 4 -
Windows Message Queuing 4 -
Windows Push Notifications 4 -
Microsoft Office 3 -
Azure Stack 2 -
Azure Virtual Machines 2 -
Desktop Windows Manager 2 -
Microsoft 365 Copilot's Business Chat 2 -
Microsoft Dynamics 365 (on-premises) 2 -
Microsoft Edge for Android 2 -
Microsoft Graphics Component 2 -
Microsoft Office SharePoint 2 -
Microsoft Office Visio 2 -
Windows DirectX 2 -
Windows Kernel 2 -
Windows Win32K - GRFX 2 -
Azure File Sync 1 -
Azure OpenAI 1 -
Azure Portal 1 -
GitHub Copilot and Visual Studio 1 -
Graphics Kernel 1 -
Kernel Streaming WOW Thunk Service Driver 1 -
Kernel Transaction Manager 1 -
Microsoft Brokering File System 1 -
Microsoft Office PowerPoint 1 -
Microsoft Teams 1 -
Remote Access Point-to-Point Protocol (PPP) EAP-TLS 1 -
Remote Desktop Server 1 -
Storage Port Driver 1 -
Web Deploy 1 -
Windows Cloud Files Mini Filter Driver 1 -
Windows Connected Devices Platform Service 1 -
Windows Distributed Transaction Coordinator 1 -
Windows File Explorer 1 -
Windows GDI+ 1 -
Windows Installer 1 -
Windows Kerberos 1 -
Windows Local Security Authority Subsystem Service (LSASS) 1 -
Windows Media 1 -
Windows NT OS Kernel 1 -
Windows NTFS 1 -
Windows NTLM 1 -
Windows PrintWorkflowUserSvc 1 -
Windows Remote Desktop Services 1 -
Windows SMB 1 -
Windows Security App 1 -
Windows StateRepository API 1 -
Windows Subsystem for Linux 1 -
Windows Win32K - ICOMP 1 -