Common Vulnerabilities and Exposures (CVE)

CVE-2025-29838

Feb 13, 2026 19:21:22 UTC

Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.

CVE-2025-29837

Feb 13, 2026 19:21:22 UTC

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

CVE-2025-29836

Feb 13, 2026 19:21:21 UTC

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-29835

Feb 13, 2026 19:21:20 UTC

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-29833

Feb 13, 2026 19:21:20 UTC

Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.

CVE-2025-29832

Feb 13, 2026 19:21:19 UTC

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-29831

Feb 13, 2026 19:21:19 UTC

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

CVE-2025-29830

Feb 13, 2026 19:21:18 UTC

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-29829

Feb 13, 2026 19:21:17 UTC

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

CVE-2025-26685

Feb 13, 2026 19:21:17 UTC

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2025-27488

Feb 13, 2026 19:21:16 UTC

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

CVE-2025-26677

Feb 13, 2026 19:21:16 UTC

Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

CVE-2025-32709

Feb 13, 2026 19:21:15 UTC

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-33072

Feb 13, 2026 19:21:15 UTC

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

CVE-2025-21264

Feb 13, 2026 19:21:14 UTC

Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.