CVE-2025-29817 Microsoft Power Automate Desktop Information Disclosure Vulnerability

Posted on Tuesday April 15, 2025

Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

 

CVE-2024-21302 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Posted on Tuesday April 15, 2025

To comprehensively address CVE-2024-21302, Microsoft has released April 2025 security updates for all supported editions of Windows. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.

 

CVE-2025-26682 ASP.NET Core and Visual Studio Denial of Service Vulnerability

Posted on Tuesday April 08, 2025

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

 

CVE-2025-24062 Microsoft DWM Core Library Elevation of Privilege Vulnerability

Posted on Tuesday April 08, 2025

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

 

CVE-2025-24060 Microsoft DWM Core Library Elevation of Privilege Vulnerability

Posted on Tuesday April 08, 2025

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

 

CVE-2025-20570 Visual Studio Code Elevation of Privilege Vulnerability

Posted on Tuesday April 08, 2025

Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

 

Page:   1...262728293031323334...172

Celebrating 35+ Years

Managed Internet Connections

Contact Us

Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016