Common Vulnerabilities and Exposures (CVE)

CVE-2025-29812

Feb 13, 2026 19:33:33 UTC

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVE-2025-29810

Feb 13, 2026 19:33:33 UTC

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

CVE-2025-29805

Feb 13, 2026 19:33:32 UTC

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

CVE-2025-29808

Feb 13, 2026 19:33:32 UTC

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2025-29809

Feb 13, 2026 19:33:31 UTC

Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

CVE-2025-29804

Feb 13, 2026 19:33:31 UTC

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

CVE-2025-29801

Feb 13, 2026 19:33:30 UTC

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

CVE-2025-29802

Feb 13, 2026 19:33:30 UTC

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

CVE-2025-29800

Feb 13, 2026 19:33:29 UTC

Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

CVE-2025-29803

Feb 13, 2026 19:33:28 UTC

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

CVE-2025-27739

Feb 13, 2026 19:33:28 UTC

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2025-27738

Feb 13, 2026 19:33:27 UTC

Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

CVE-2025-27737

Feb 13, 2026 19:33:27 UTC

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-27736

Feb 13, 2026 19:33:26 UTC

Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.

CVE-2025-27735

Feb 13, 2026 19:33:25 UTC

Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.