CVE-2025-59245 Microsoft SharePoint Online Elevation of Privilege Vulnerability

Information published.


CVE-2025-54099 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Acknowledgement added. This is an informational change only.


CVE-2025-64655 Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.


CVE-2025-62453 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.


CVE-2025-62222 Agentic AI and Visual Studio Code Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command (‘command injection’) in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.


CVE-2025-62211 Dynamics 365 Field Service (online) Spoofing Vulnerability

Improper neutralization of input during web page generation (‘cross-site scripting’) in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.


CVE-2025-62205 Microsoft Office Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.


CVE-2025-59504 Azure Monitor Agent Remote Code Execution Vulnerability

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.


CVE-2025-60713 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.


CVE-2025-59240 Microsoft Excel Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

AbuseIPDB Contributor Badge