Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2025-25004: PowerShell Elevation of Privilege Vulnerability

**What privileges could be gained by an attacker who successfully exploited the vulnerability?** An attacker who successfully exploited this vulnerability could create, modify, or delete files in the security context of the "NT AUTHORITY\\SYSTEM" account.

Microsoft Security Response Center
#vulnerability#auth#Microsoft PowerShell#Security Vulnerability
CVE-2025-48813: Virtual Secure Mode Spoofing Vulnerability

Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

CVE-2025-59502: Remote Procedure Call Denial of Service Vulnerability

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

CVE-2025-53139: Windows Hello Security Feature Bypass Vulnerability

Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-55328: Windows Hyper-V Elevation of Privilege Vulnerability

**What privileges could be gained by an attacker who successfully exploited this vulnerability?** An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.