Common Vulnerabilities and Exposures (CVE)

CVE-2025-55686

Feb 13, 2026 23:11:37 UTC

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

CVE-2025-55685

Feb 13, 2026 23:11:36 UTC

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

CVE-2025-55681

Feb 13, 2026 23:11:35 UTC

Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2025-55677

Feb 13, 2026 23:11:35 UTC

Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

CVE-2025-55676

Feb 13, 2026 23:11:34 UTC

Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.

CVE-2025-55340

Feb 13, 2026 23:11:34 UTC

Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

CVE-2025-55339

Feb 13, 2026 23:11:33 UTC

Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

CVE-2025-55336

Feb 13, 2026 23:11:32 UTC

Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

CVE-2025-55335

Feb 13, 2026 23:11:32 UTC

Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

CVE-2025-55333

Feb 13, 2026 23:11:31 UTC

Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2025-55325

Feb 13, 2026 23:11:30 UTC

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

CVE-2025-55320

Feb 13, 2026 23:11:30 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2025-24052

Feb 13, 2026 23:11:29 UTC

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed i...

CVE-2025-24990

Feb 13, 2026 23:11:28 UTC

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed i...

CVE-2025-55315

Feb 13, 2026 23:11:28 UTC

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.