Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

CVE-2025-58736: Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

Use after free in Imebroker allows an authorized attacker to execute code locally.

Microsoft Security Response Center
#vulnerability#rce#auth#Inbox COM Objects#Security Vulnerability
CVE-2025-58720: Windows Cryptographic Services Information Disclosure Vulnerability

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVE-2025-58727: Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

CVE-2025-55696: NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.