Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2025-27742: NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.

Microsoft Security Response Center
#vulnerability#windows#auth#Windows NTFS#Security Vulnerability
CVE-2025-27744: Microsoft Office Elevation of Privilege Vulnerability

**Is the Preview Pane an attack vector for this vulnerability?** No, the Preview Pane is not an attack vector.

CVE-2025-26688: Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

**What privileges could be gained by an attacker who successfully exploited this vulnerability?** An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

CVE-2025-26686: Windows TCP/IP Remote Code Execution Vulnerability

**According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?** Successful exploitation of this vulnerability requires an attacker to win a race condition and also to take additional actions prior to exploitation to prepare the target environment.

CVE-2025-26667: Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.