CVEs (1,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 22h2+5 moreSep 25, 2025 Sep 18, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 2Windows 11 24h2 Windows Server 2025Sep 25, 2025 Sep 18, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
1Microsoft 2Windows 11 24h2 Windows Server 2025Sep 25, 2025 Sep 18, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreSep 12, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 17, 2025 Sep 9, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privile...Show more |
1Microsoft 8Windows 10 21h2 Windows 10 22h2Windows 11 22h2+5 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreSep 12, 2025 Sep 9, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreSep 12, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreSep 12, 2025 Sep 9, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreSep 12, 2025 Sep 9, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreSep 15, 2025 Sep 9, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreOct 2, 2025 Sep 9, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. |