CVE-2025-32706 |
Description: Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.
CVSS: HIGH (7.8) EPSS Score: 10.51%
May 13th, 2025 (21 days ago)
|
CVE-2025-30397 |
Description: Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.
CVSS: HIGH (7.5) EPSS Score: 10.87%
May 13th, 2025 (21 days ago)
|
CVE-2025-32709 |
Description: Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.
CVSS: HIGH (7.8) EPSS Score: 4.28%
May 13th, 2025 (21 days ago)
|
CVE-2025-32709 |
🚨 Marked as known exploited on May 13th, 2025 (21 days ago).
Description: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS: HIGH (7.8) EPSS Score: 4.28%
May 13th, 2025 (22 days ago)
|
CVE-2025-32707 |
Description: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVSS: HIGH (7.8) EPSS Score: 0.06%
May 13th, 2025 (22 days ago)
|
CVE-2025-32706 |
🚨 Marked as known exploited on May 13th, 2025 (21 days ago).
Description: Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVSS: HIGH (7.8) EPSS Score: 10.51%
May 13th, 2025 (22 days ago)
|
CVE-2025-32705 |
Description: Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
CVSS: HIGH (7.8) EPSS Score: 0.06%
May 13th, 2025 (22 days ago)
|
CVE-2025-32704 |
Description: Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS: HIGH (8.4) EPSS Score: 0.05%
May 13th, 2025 (22 days ago)
|
CVE-2025-32702 |
Description: Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
CVSS: HIGH (7.8) EPSS Score: 0.05%
May 13th, 2025 (22 days ago)
|
CVE-2025-32701 |
🚨 Marked as known exploited on May 13th, 2025 (21 days ago).
Description: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVSS: HIGH (7.8) EPSS Score: 4.24%
May 13th, 2025 (22 days ago)
|