CVE-2025-27727 Windows Installer Elevation of Privilege Vulnerability
Published April 8, 2025
Improper link resolution before file access (‘link following’) in Windows Installer allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Improper link resolution before file access (‘link following’) in Windows Installer allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Published April 8, 2025
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Published April 8, 2025
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Published April 8, 2025
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
Published April 8, 2025
Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published April 8, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Published April 8, 2025
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.