Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2025-27743: Microsoft System Center Elevation of Privilege Vulnerability

**What Microsoft System Center Products are affected by this vulnerability?** This vulnerability affects the following products under the Microsoft System Center: * System Center Operations Manager * System Center Service Manager * System Center Orchestrator * System Center Data protection Manager * System Center Virtual Machine Manager For more information about these products see System Center documentation.

Microsoft Security Response Center
#vulnerability#mac#microsoft#System Center#Security Vulnerability
CVE-2025-27748: Microsoft Office Remote Code Execution Vulnerability

**According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?** The word **Remote** in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. For example, when the score indicates that the **Attack Vector** is **Local** and **User Interaction** is **Required**, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.

CVE-2025-27746: Microsoft Office Remote Code Execution Vulnerability

**According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?** The word **Remote** in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. For example, when the score indicates that the **Attack Vector** is **Local** and **User Interaction** is **Required**, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.

CVE-2025-27742: NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.

CVE-2025-27744: Microsoft Office Elevation of Privilege Vulnerability

**Is the Preview Pane an attack vector for this vulnerability?** No, the Preview Pane is not an attack vector.

CVE-2025-27740: Active Directory Certificate Services Elevation of Privilege Vulnerability

**How could an attacker exploit this vulnerability?** An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow elevation of privilege to System.