Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2025
CVE-2025-26633
Known exploited
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
CVSS Score
7.0
EPSS Score
0.425
Published
2025-03-11
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.005
Published
2025-03-11
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.005
Published
2025-03-11
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2025-03-11
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVSS Score
7.3
EPSS Score
0.003
Published
2025-03-11
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
CVSS Score
7.1
EPSS Score
0.003
Published
2025-03-11
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2025-03-11
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
CVSS Score
4.4
EPSS Score
0.001
Published
2025-03-11
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVSS Score
7.3
EPSS Score
0.003
Published
2025-03-11
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVSS Score
7.3
EPSS Score
0.003
Published
2025-03-11


Contact Us

Shodan ® - All rights reserved