Published December 9, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.
Published December 9, 2025
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published December 9, 2025
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Published December 9, 2025
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Published December 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.