Security Vulnerabilities
- CVEs Published In July 2025
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.