Security
Headlines
HeadlinesLatestCVEs

Latest News

CVE-2025-26640: Windows Digital Media Elevation of Privilege Vulnerability

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Microsoft Security Response Center
#vulnerability#windows#git#auth#Windows Digital Media#Security Vulnerability
CVE-2025-26637: BitLocker Security Feature Bypass Vulnerability

**Are the updates for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems currently available?** The security update for Windows 10 for x64-based Systems and Windows 10 for 32-bit Systems are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.

CVE-2025-26635: Windows Hello Security Feature Bypass Vulnerability

**What kind of security feature could be bypassed by successfully exploiting this vulnerability?** An attacker who successfully exploited this vulnerability could bypass the Windows Hello security feature. **Where can I find more information about Windows Hello?** Please see Windows Hello | Microsoft Learn for more details.

CVE-2025-25002: Azure Local Cluster Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** The type of information that could be disclosed if an attacker successfully exploited this vulnerability is user tokens and other potentially sensitive information.