Common Vulnerabilities and Exposures (CVE)

CVE-2025-64660

Feb 13, 2026 20:46:18 UTC

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

CVE-2025-62453

Feb 13, 2026 20:46:17 UTC

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

CVE-2025-60721

Feb 13, 2026 20:46:16 UTC

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

CVE-2025-62449

Feb 13, 2026 20:46:16 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.

CVE-2025-62222

Feb 13, 2026 20:46:15 UTC

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.

CVE-2025-62213

Feb 13, 2026 20:46:15 UTC

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-62215

Feb 13, 2026 20:46:14 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2025-62214

Feb 13, 2026 20:46:14 UTC

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.

CVE-2025-62211

Feb 13, 2026 20:46:13 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

CVE-2025-59499

Feb 13, 2026 20:46:13 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVE-2025-62209

Feb 13, 2026 20:46:12 UTC

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

CVE-2025-62208

Feb 13, 2026 20:46:11 UTC

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

CVE-2025-62205

Feb 13, 2026 20:46:11 UTC

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-62204

Feb 13, 2026 20:46:10 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2025-62203

Feb 13, 2026 20:46:10 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.