Patch Tuesday Archive
Patch Tuesday October 2025
Total CVEs
180
Critical
18
Important
160
Exploited
2
Publicly Disclosed
1
All CVEs this month 180
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2025-47989 | Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important | 7 |
Azure Connected Machine Agent | - | - | - |
| CVE-2025-48004 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Brokering File System | - | - | - |
| CVE-2025-50174 | Windows Device Association Broker Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Device Association Broker service | - | - | - |
| CVE-2025-53782 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2025-55247 | .NET Elevation of Privilege Vulnerability | Important | 7.3 |
.NET | - | - | - |
| CVE-2025-55315 | ASP.NET Security Feature Bypass Vulnerability | Important | 9.9 |
ASP.NET Core | - | - | - |
| CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Agere Windows Modem Driver | Yes | - | - |
| CVE-2025-24052 | Windows Agere Modem Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Agere Windows Modem Driver | - | Yes | - |
| CVE-2025-55320 | Configuration Manager Elevation of Privilege Vulnerability | Important | 6.8 |
Microsoft Configuration Manager | - | - | - |
| CVE-2025-55325 | Windows Storage Management Provider Information Disclosure Vulnerability | Important | 5.5 |
Windows Storage Management Provider | - | - | - |
| CVE-2025-55333 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-55335 | Windows NTFS Elevation of Privilege Vulnerability | Important | 7 |
Windows NTFS | - | - | - |
| CVE-2025-55336 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2025-55338 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-55339 | Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NDIS | - | - | - |
| CVE-2025-55340 | Windows Remote Desktop Protocol Security Feature Bypass | Important | 7 |
Windows Remote Desktop Protocol | - | - | - |
| CVE-2025-55676 | Windows USB Video Class System Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows USB Video Driver | - | - | - |
| CVE-2025-55677 | Windows Device Association Broker Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Device Association Broker service | - | - | - |
| CVE-2025-55681 | Desktop Windows Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM | - | - | - |
| CVE-2025-55685 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55686 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55687 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Important | 7 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2025-55689 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55700 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Important | 4.3 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2025-55701 | Windows Authentication Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | - | - |
| CVE-2025-58715 | Windows Speech Runtime Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Windows Speech | - | - | - |
| CVE-2025-58716 | Windows Speech Runtime Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Windows Speech | - | - | - |
| CVE-2025-58717 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Important | 4.3 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2025-58719 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Important | 4.7 |
Connected Devices Platform Service (Cdpsvc) | - | - | - |
| CVE-2025-58722 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM | - | - | - |
| CVE-2025-58728 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Bluetooth Service | - | - | - |
| CVE-2025-58732 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58735 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-59185 | NTLM Hash Disclosure Spoofing Vulnerability | Important | 6.5 |
Windows Core Shell | - | - | - |
| CVE-2025-59186 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2025-59195 | Microsoft Graphics Component Denial of Service Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2025-59196 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | Important | 7 |
Windows SSDP Service | - | - | - |
| CVE-2025-59199 | Software Protection Platform (SPP) Elevation of Privilege Vulnerability | Important | 7.8 |
Software Protection Platform (SPP) | - | - | - |
| CVE-2025-59200 | Data Sharing Service Spoofing Vulnerability | Important | 7.7 |
Data Sharing Service Client | - | - | - |
| CVE-2025-59201 | Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability | Important | 7.8 |
Network Connection Status Indicator (NCSI) | - | - | Yes |
| CVE-2025-59202 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Important | 7 |
Windows Remote Desktop Services | - | - | - |
| CVE-2025-59204 | Windows Management Services Information Disclosure Vulnerability | Important | 5.5 |
Windows Management Services | - | - | - |
| CVE-2025-59206 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | Important | 7.4 |
Windows Resilient File System (ReFS) Deduplication Service | - | - | - |
| CVE-2025-59207 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2025-59211 | Windows Push Notification Information Disclosure Vulnerability | Important | 5.5 |
Windows Push Notification Core | - | - | - |
| CVE-2025-59228 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2025-59231 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59233 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59234 | Microsoft Office Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-59235 | Microsoft Excel Information Disclosure Vulnerability | Important | 7.1 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59236 | Microsoft Excel Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59237 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2025-59242 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2025-49708 | Microsoft Graphics Component Elevation of Privilege Vulnerability | Critical | 9.9 |
Microsoft Graphics Component | - | - | - |
| CVE-2025-59243 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59249 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2025-59250 | JDBC Driver for SQL Server Spoofing Vulnerability | Important | 8.1 |
JDBC Driver for SQL Server | - | - | - |
| CVE-2025-59254 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2025-59255 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2025-59257 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | Important | 6.5 |
Windows Local Session Manager (LSM) | - | - | - |
| CVE-2025-59258 | Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability | Important | 6.2 |
Active Directory Federation Services | - | - | - |
| CVE-2025-59259 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | Important | 6.5 |
Windows Local Session Manager (LSM) | - | - | - |
| CVE-2025-59277 | Windows Authentication Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Authentication Methods | - | - | - |
| CVE-2025-59280 | Windows SMB Client Tampering Vulnerability | Important | 3.1 |
Windows SMB Client | - | - | - |
| CVE-2025-47979 | Microsoft Failover Cluster Information Disclosure Vulnerability | Important | 5.5 |
Windows Failover Cluster | - | - | - |
| CVE-2025-59281 | Xbox Gaming Services Elevation of Privilege Vulnerability | Important | 7.8 |
XBox Gaming Services | - | - | - |
| CVE-2025-59282 | Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-59284 | Windows NTLM Spoofing Vulnerability | Important | 5.5 |
Windows NTLM | - | - | - |
| CVE-2025-59288 | Playwright Spoofing Vulnerability | Moderate | 5.3 |
Github: Playwright | - | - | - |
| CVE-2025-59290 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Bluetooth Service | - | - | - |
| CVE-2025-59291 | Confidential Azure Container Instances Elevation of Privilege Vulnerability | Critical | 8.2 |
Confidential Azure Container Instances | - | - | - |
| CVE-2025-59292 | Azure Compute Gallery Elevation of Privilege Vulnerability | Critical | 8.2 |
Confidential Azure Container Instances | - | - | - |
| CVE-2025-59294 | Windows Taskbar Live Preview Information Disclosure Vulnerability | Important | 4.6 |
Windows Taskbar Live | - | - | - |
| CVE-2025-59295 | Windows URL Parsing Remote Code Execution Vulnerability | Important | 8.8 |
Internet Explorer | - | - | - |
| CVE-2025-59494 | Azure Monitor Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Monitor Agent | - | - | - |
| CVE-2025-59502 | Remote Procedure Call Denial of Service Vulnerability | Moderate | 7.5 |
Windows Remote Procedure Call | - | - | - |
| CVE-2025-48813 | Virtual Secure Mode Spoofing Vulnerability | Important | 4.7 |
Virtual Secure Mode | - | - | - |
| CVE-2025-25004 | PowerShell Elevation of Privilege Vulnerability | Important | 7.3 |
Microsoft PowerShell | - | - | - |
| CVE-2025-53717 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Important | 7 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2025-50152 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2025-53150 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Digital Media | - | - | - |
| CVE-2025-50175 | Windows Digital Media Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Digital Media | - | - | - |
| CVE-2025-53139 | Windows Hello Security Feature Bypass Vulnerability | Important | 7.1 |
Windows Hello | - | - | - |
| CVE-2025-53768 | Xbox IStorageService Elevation of Privilege Vulnerability | Important | 7.8 |
Xbox | - | - | - |
| CVE-2025-55240 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.3 |
Visual Studio | - | - | - |
| CVE-2025-55248 | .NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability | Important | 5.7 |
.NET, .NET Framework, Visual Studio | - | - | - |
| CVE-2025-55326 | Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability | Important | 7.5 |
Connected Devices Platform Service (Cdpsvc) | - | - | - |
| CVE-2025-55328 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 7 |
Windows Hyper-V | - | - | - |
| CVE-2025-55330 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-55331 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55332 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-55334 | Windows Kernel Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2025-55337 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-55678 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows DirectX | - | - | - |
| CVE-2025-55679 | Windows Kernel Information Disclosure Vulnerability | Important | 4.7 |
Windows Kernel | - | - | - |
| CVE-2025-55680 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Cloud Files Mini Filter Driver | - | - | Yes |
| CVE-2025-55682 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 4.6 |
Windows BitLocker | - | - | - |
| CVE-2025-55684 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55688 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55690 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55691 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | Important | 7 |
Windows PrintWorkflowUserSvc | - | - | - |
| CVE-2025-55692 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Error Reporting | - | - | - |
| CVE-2025-55693 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2025-55694 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Error Reporting | - | - | - |
| CVE-2025-55695 | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | Important | 3.3 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2025-55696 | NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability | Important | 7 |
NtQueryInformation Token function (ntifs.h) | - | - | - |
| CVE-2025-55697 | Azure Local Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Local | - | - | - |
| CVE-2025-55698 | DirectX Graphics Kernel Denial of Service Vulnerability | Important | 7.7 |
Windows DirectX | - | - | - |
| CVE-2025-55699 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2025-58714 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2025-58718 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2025-58720 | Windows Cryptographic Services Information Disclosure Vulnerability | Important | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2025-58724 | Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Connected Machine Agent | - | - | - |
| CVE-2025-58725 | Windows COM+ Event System Service Elevation of Privilege Vulnerability | Important | 7 |
Windows COM | - | - | - |
| CVE-2025-58726 | Windows SMB Server Elevation of Privilege Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2025-58727 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Connected Devices Platform Service | - | - | - |
| CVE-2025-58729 | Windows Local Session Manager (LSM) Denial of Service Vulnerability | Important | 6.5 |
Windows Local Session Manager (LSM) | - | - | - |
| CVE-2025-58730 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58731 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58733 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58734 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58736 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58737 | Remote Desktop Protocol Remote Code Execution Vulnerability | Important | 7 |
Windows Remote Desktop | - | - | - |
| CVE-2025-58738 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2025-58739 | Microsoft Windows File Explorer Spoofing Vulnerability | Important | 6.5 |
Windows File Explorer | - | - | - |
| CVE-2025-59187 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2025-59188 | Microsoft Failover Cluster Information Disclosure Vulnerability | Important | 5.5 |
Windows Failover Cluster | - | - | - |
| CVE-2025-59189 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Brokering File System | - | - | - |
| CVE-2025-59190 | Windows Search Service Denial of Service Vulnerability | Important | 5.5 |
Microsoft Windows Search Component | - | - | - |
| CVE-2025-59191 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Important | 7.8 |
Connected Devices Platform Service (Cdpsvc) | - | - | - |
| CVE-2025-59192 | Storport.sys Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Storport.sys Driver | - | - | - |
| CVE-2025-59193 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7 |
Windows Management Services | - | - | - |
| CVE-2025-59194 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2025-59197 | Windows ETL Channel Information Disclosure Vulnerability | Important | 5.5 |
Windows ETL Channel | - | - | - |
| CVE-2025-59198 | Windows Search Service Denial of Service Vulnerability | Important | 5 |
Microsoft Windows Search Component | - | - | - |
| CVE-2025-59203 | Windows State Repository API Server File Information Disclosure Vulnerability | Important | 5.5 |
Windows StateRepository API | - | - | - |
| CVE-2025-59205 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2025-59208 | Windows MapUrlToZone Information Disclosure Vulnerability | Important | 7.1 |
Windows MapUrlToZone | - | - | - |
| CVE-2025-59209 | Windows Push Notification Information Disclosure Vulnerability | Important | 5.5 |
Windows Push Notification Core | - | - | - |
| CVE-2025-59210 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | Important | 7.4 |
Windows Resilient File System (ReFS) Deduplication Service | - | - | - |
| CVE-2025-59213 | Configuration Manager Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Configuration Manager | - | - | - |
| CVE-2025-59214 | Microsoft Windows File Explorer Spoofing Vulnerability | Important | 6.5 |
Windows File Explorer | - | - | - |
| CVE-2025-59221 | Microsoft Word Remote Code Execution Vulnerability | Important | 7 |
Microsoft Office Word | - | - | - |
| CVE-2025-59222 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2025-59223 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59224 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59225 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59226 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2025-59227 | Microsoft Office Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office | - | - | - |
| CVE-2025-59229 | Microsoft Office Denial of Service Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2025-59232 | Microsoft Excel Information Disclosure Vulnerability | Important | 7.1 |
Microsoft Office Excel | - | - | - |
| CVE-2025-59238 | Microsoft PowerPoint Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office PowerPoint | - | - | - |
| CVE-2025-59241 | Windows Health and Optimized Experiences Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Health and Optimized Experiences Service | - | - | - |
| CVE-2025-59244 | NTLM Hash Disclosure Spoofing Vulnerability | Important | 6.5 |
Windows Core Shell | - | - | - |
| CVE-2025-59248 | Microsoft Exchange Server Spoofing Vulnerability | Important | 7.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | Yes | - | - |
| CVE-2025-59253 | Windows Search Service Denial of Service Vulnerability | Important | 5.5 |
Microsoft Windows Search Component | - | - | - |
| CVE-2025-59260 | Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Failover Cluster Virtual Driver | - | - | - |
| CVE-2025-59261 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Graphics Component | - | - | - |
| CVE-2025-59275 | Windows Authentication Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Authentication Methods | - | - | - |
| CVE-2025-59278 | Windows Authentication Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Authentication Methods | - | - | - |
| CVE-2025-59285 | Azure Monitor Agent Elevation of Privilege Vulnerability | Important | 7 |
Azure Monitor Agent | - | - | - |
| CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Server Update Service | - | - | - |
| CVE-2025-59289 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Bluetooth Service | - | - | - |
| CVE-2025-59497 | Microsoft Defender for Linux Denial of Service Vulnerability | Important | 4.7 |
Microsoft Defender for Linux | - | - | - |
| CVE-2025-59218 | Azure Entra ID Elevation of Privilege Vulnerability | Critical | 9.6 |
Azure Entra ID | - | - | - |
| CVE-2025-59246 | Azure Entra ID Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Entra ID | - | - | - |
| CVE-2025-59247 | Azure PlayFab Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure PlayFab | - | - | - |
| CVE-2025-59252 | M365 Copilot Information Disclosure Vulnerability | Critical | 9.3 |
Copilot | - | - | - |
| CVE-2025-59271 | Redis Enterprise Elevation of Privilege Vulnerability | Critical | 8.7 |
Redis Enterprise | - | - | - |
| CVE-2025-59272 | Copilot Information Disclosure Vulnerability | Critical | 9.3 |
Copilot | - | - | - |
| CVE-2025-55321 | Azure Monitor Log Analytics Spoofing Vulnerability | Critical | 9.3 |
Azure Monitor | - | - | - |
| CVE-2025-59286 | Copilot Information Disclosure Vulnerability | Critical | 9.3 |
Copilot | - | - | - |
| CVE-2025-59273 | Azure Event Grid System Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Event Grid | - | - | - |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Compute Gallery | - | - | - |
| CVE-2025-59500 | Azure Notification Service Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure Notification Service | - | - | - |
| CVE-2025-59501 | Microsoft Configuration Manager Spoofing Vulnerability | Important | 4.8 |
Microsoft Configuration Manager | - | - | - |
| CVE-2025-60711 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 6.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2025-59184 | Storage Spaces Direct Information Disclosure Vulnerability | Important | 5.5 |
Windows High Availability Services | - | - | - |
| CVE-2025-55683 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 87 | 10 |
| Remote Code Execution | 30 | 4 |
| Information Disclosure | 26 | - |
| Spoofing | 15 | 4 |
| Denial of Service | 11 | - |
| Security Feature Bypass | 10 | - |
| Tampering | 1 | - |
Affected Products 98
| Product | CVEs | Exploited |
|---|---|---|
| Windows Kernel | 10 | - |
| Inbox COM Objects | 9 | - |
| Microsoft Office Excel | 9 | - |
| Windows PrintWorkflowUserSvc | 8 | - |
| Windows BitLocker | 6 | - |
| Microsoft Graphics Component | 4 | - |
| Connected Devices Platform Service (Cdpsvc) | 3 | - |
| Copilot | 3 | - |
| Microsoft Configuration Manager | 3 | - |
| Microsoft Exchange Server | 3 | - |
| Microsoft Office | 3 | - |
| Microsoft Windows Search Component | 3 | - |
| Windows Authentication Methods | 3 | - |
| Windows Bluetooth Service | 3 | - |
| Windows Local Session Manager (LSM) | 3 | - |
| Agere Windows Modem Driver | 2 | 1 |
| Azure Connected Machine Agent | 2 | - |
| Azure Entra ID | 2 | - |
| Azure Monitor Agent | 2 | - |
| Confidential Azure Container Instances | 2 | - |
| Microsoft Brokering File System | 2 | - |
| Microsoft Office SharePoint | 2 | - |
| Microsoft Office Word | 2 | - |
| Microsoft Windows Speech | 2 | - |
| Windows Ancillary Function Driver for WinSock | 2 | - |
| Windows Cloud Files Mini Filter Driver | 2 | - |
| Windows Core Shell | 2 | - |
| Windows DWM | 2 | - |
| Windows DWM Core Library | 2 | - |
| Windows Device Association Broker service | 2 | - |
| Windows Digital Media | 2 | - |
| Windows DirectX | 2 | - |
| Windows Error Reporting | 2 | - |
| Windows Failover Cluster | 2 | - |
| Windows File Explorer | 2 | - |
| Windows Management Services | 2 | - |
| Windows Push Notification Core | 2 | - |
| Windows Resilient File System (ReFS) Deduplication Service | 2 | - |
| Windows Routing and Remote Access Service (RRAS) | 2 | - |
| .NET | 1 | - |
| .NET, .NET Framework, Visual Studio | 1 | - |
| ASP.NET Core | 1 | - |
| Active Directory Federation Services | 1 | - |
| Azure Compute Gallery | 1 | - |
| Azure Event Grid | 1 | - |
| Azure Local | 1 | - |
| Azure Monitor | 1 | - |
| Azure Notification Service | 1 | - |
| Azure PlayFab | 1 | - |
| Data Sharing Service Client | 1 | - |
| Github: Playwright | 1 | - |
| Internet Explorer | 1 | - |
| JDBC Driver for SQL Server | 1 | - |
| Microsoft Defender for Linux | 1 | - |
| Microsoft Edge (Chromium-based) | 1 | - |
| Microsoft Failover Cluster Virtual Driver | 1 | - |
| Microsoft Office PowerPoint | 1 | - |
| Microsoft Office Visio | 1 | - |
| Microsoft PowerShell | 1 | - |
| Microsoft Windows | 1 | - |
| Network Connection Status Indicator (NCSI) | 1 | - |
| NtQueryInformation Token function (ntifs.h) | 1 | - |
| Redis Enterprise | 1 | - |
| Remote Desktop Client | 1 | - |
| Software Protection Platform (SPP) | 1 | - |
| Storport.sys Driver | 1 | - |
| Virtual Secure Mode | 1 | - |
| Visual Studio | 1 | - |
| Windows COM | 1 | - |
| Windows Connected Devices Platform Service | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows ETL Channel | 1 | - |
| Windows Health and Optimized Experiences Service | 1 | - |
| Windows Hello | 1 | - |
| Windows High Availability Services | 1 | - |
| Windows Hyper-V | 1 | - |
| Windows MapUrlToZone | 1 | - |
| Windows NDIS | 1 | - |
| Windows NTFS | 1 | - |
| Windows NTLM | 1 | - |
| Windows Remote Access Connection Manager | 1 | 1 |
| Windows Remote Desktop | 1 | - |
| Windows Remote Desktop Protocol | 1 | - |
| Windows Remote Desktop Services | 1 | - |
| Windows Remote Procedure Call | 1 | - |
| Windows Resilient File System (ReFS) | 1 | - |
| Windows SMB Client | 1 | - |
| Windows SMB Server | 1 | - |
| Windows SSDP Service | 1 | - |
| Windows Server Update Service | 1 | - |
| Windows StateRepository API | 1 | - |
| Windows Storage Management Provider | 1 | - |
| Windows Taskbar Live | 1 | - |
| Windows USB Video Driver | 1 | - |
| Windows Virtualization-Based Security (VBS) Enclave | 1 | - |
| Windows WLAN Auto Config Service | 1 | - |
| XBox Gaming Services | 1 | - |
| Xbox | 1 | - |