Common Vulnerabilities and Exposures (CVE)

CVE-2025-62465

Feb 20, 2026 15:59:25 UTC

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

CVE-2025-62464

Feb 20, 2026 15:59:24 UTC

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2025-62463

Feb 20, 2026 15:59:23 UTC

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

CVE-2025-62462

Feb 20, 2026 15:59:22 UTC

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2025-62461

Feb 20, 2026 15:59:22 UTC

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-62455

Feb 20, 2026 15:59:21 UTC

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2025-59517

Feb 20, 2026 15:59:20 UTC

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-59516

Feb 20, 2026 15:59:20 UTC

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-62224

Feb 20, 2026 15:59:19 UTC

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.

CVE-2025-64669

Feb 20, 2026 15:59:19 UTC

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

CVE-2025-64673

Feb 20, 2026 15:59:18 UTC

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-64670

Feb 20, 2026 15:59:17 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

CVE-2025-64666

Feb 20, 2026 15:59:17 UTC

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CVE-2025-64667

Feb 20, 2026 15:59:16 UTC

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-64658

Feb 20, 2026 15:59:15 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.