Common Vulnerabilities and Exposures (CVE)

CVE-2025-29978

Feb 13, 2026 19:20:58 UTC

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-29977

Feb 13, 2026 19:20:57 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-29976

Feb 13, 2026 19:20:57 UTC

Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.

CVE-2025-29975

Feb 13, 2026 19:20:56 UTC

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

CVE-2025-29973

Feb 13, 2026 19:20:56 UTC

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

CVE-2025-29971

Feb 13, 2026 19:20:55 UTC

Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.

CVE-2025-29970

Feb 13, 2026 19:20:54 UTC

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2025-29969

Feb 13, 2026 19:20:54 UTC

Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.

CVE-2025-29968

Feb 13, 2026 19:20:53 UTC

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

CVE-2025-29967

Feb 13, 2026 19:20:52 UTC

Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

CVE-2025-29966

Feb 13, 2026 19:20:52 UTC

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

CVE-2025-29964

Feb 13, 2026 19:20:51 UTC

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

CVE-2025-29960

Feb 13, 2026 19:20:50 UTC

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-29959

Feb 13, 2026 19:20:50 UTC

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-29825

Feb 13, 2026 19:20:49 UTC

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.