Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2025-2884: Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation

Out-of-bounds read in TCG TPM2.0 allows an authorized attacker to disclose information locally.

Microsoft Security Response Center
#vulnerability#auth#TCG TPM2.0#Security Vulnerability
CVE-2025-59205: Windows Graphics Component Elevation of Privilege Vulnerability

**According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?** Successful exploitation of this vulnerability requires an attacker to win a race condition.

CVE-2025-59203: Windows State Repository API Server File Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

CVE-2025-59213: Configuration Manager Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges locally.

CVE-2025-59197: Windows ETL Channel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.