Common Vulnerabilities and Exposures (CVE)

CVE-2025-49694

Jul 11, 2025 22:32:08 UTC

Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2025-49691

Jul 11, 2025 22:32:07 UTC

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.

CVE-2025-49690

Jul 11, 2025 22:32:06 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.

CVE-2025-49689

Jul 11, 2025 22:32:06 UTC

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

CVE-2025-49688

Jul 11, 2025 22:32:05 UTC

Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-49687

Jul 11, 2025 22:32:05 UTC

Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

CVE-2025-49686

Jul 11, 2025 22:32:04 UTC

Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

CVE-2025-49677

Jul 11, 2025 22:32:03 UTC

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2025-49676

Jul 11, 2025 22:32:02 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-49674

Jul 11, 2025 22:32:02 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-49672

Jul 11, 2025 22:32:01 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-49671

Jul 11, 2025 22:32:00 UTC

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-49670

Jul 11, 2025 22:32:00 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-49661

Jul 11, 2025 22:31:59 UTC

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-49658

Jul 11, 2025 22:31:59 UTC

Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.