CVE-2025-27474 |
Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVSS: MEDIUM (6.5) EPSS Score: 0.17%
April 8th, 2025 (11 days ago)
|
CVE-2025-27472 |
Description: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
CVSS: MEDIUM (5.4) EPSS Score: 0.1%
April 8th, 2025 (11 days ago)
|
CVE-2025-27471 |
Description: Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
CVSS: MEDIUM (5.9) EPSS Score: 0.05%
April 8th, 2025 (11 days ago)
|
CVE-2025-26681 |
Description: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVSS: MEDIUM (6.7) EPSS Score: 0.05%
April 8th, 2025 (11 days ago)
|
CVE-2025-26676 |
Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVSS: MEDIUM (6.5) EPSS Score: 0.06%
April 8th, 2025 (11 days ago)
|
CVE-2025-26672 |
Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVSS: MEDIUM (6.5) EPSS Score: 0.06%
April 8th, 2025 (11 days ago)
|
CVE-2025-26667 |
Description: Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVSS: MEDIUM (6.5) EPSS Score: 0.06%
April 8th, 2025 (11 days ago)
|
CVE-2025-26664 |
Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVSS: MEDIUM (6.5) EPSS Score: 0.06%
April 8th, 2025 (11 days ago)
|
CVE-2025-26651 |
Description: Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
CVSS: MEDIUM (6.5) EPSS Score: 2.48%
April 8th, 2025 (11 days ago)
|
CVE-2025-26644 |
Description: Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
CVSS: MEDIUM (5.1) EPSS Score: 0.05%
April 8th, 2025 (11 days ago)
|