Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

CVE-2025-26685: Microsoft Defender for Identity Spoofing Vulnerability

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to elevate privileges locally.

Microsoft Security Response Center
#vulnerability#microsoft#auth#Microsoft Defender for Identity#Security Vulnerability
CVE-2025-29836: Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

**According to the CVSS metric, user interaction is required (UI:R) and privileges required are none (PR:N). What does that mean for this vulnerability?** An unauthorized attacker must wait for a user to initiate a connection.

CVE-2025-29837: Windows Installer Information Disclosure Vulnerability

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.