[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> CVE-2025-55339 Windows Network Driver Interface Specification Driver Elevation of Privilege Vulnerability
Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
> CVE-2025-55340 Windows Remote Desktop Protocol Security Feature Bypass
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.
> CVE-2025-55676 Windows USB Video Class System Driver Information Disclosure Vulnerability
Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.
> CVE-2025-55677 Windows Device Association Broker Service Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
> CVE-2025-55681 Desktop Windows Manager Elevation of Privilege Vulnerability
Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.
> CVE-2025-55685 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
> CVE-2025-55686 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
> CVE-2025-55687 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
> CVE-2025-55689 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
> CVE-2025-55700 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
> CVE-2025-55701 Windows Authentication Elevation of Privilege Vulnerability
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
> CVE-2025-58715 Windows Speech Runtime Elevation of Privilege Vulnerability
Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
> CVE-2025-58716 Windows Speech Runtime Elevation of Privilege Vulnerability
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
> CVE-2025-58717 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
> CVE-2025-58719 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
> CVE-2025-58722 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
> CVE-2025-58728 Windows Bluetooth Service Elevation of Privilege Vulnerability
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
> CVE-2025-58732 Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
> CVE-2025-58735 Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
> CVE-2025-59185 NTLM Hash Disclosure Spoofing Vulnerability
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.