Published December 9, 2025
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Published December 9, 2025
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
Published December 9, 2025
Access of resource using incompatible type (‘type confusion’) in Microsoft Office allows an unauthorized attacker to execute code locally.
Published December 9, 2025
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published December 9, 2025
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.