Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

CVE-2025-59284: Windows NTLM Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

Microsoft Security Response Center
#vulnerability#windows#auth#Windows NTLM#Security Vulnerability
CVE-2025-54132: GitHub CVE-2025-54132: Arbitrary Image Fetch in Mermaid Diagram Tool

Ai command injection in Visual Studio allows an authorized attacker to disclose information over a network.

CVE-2025-59237: Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2025-59257: Windows Local Session Manager (LSM) Denial of Service Vulnerability

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

CVE-2025-59250: JDBC Driver for SQL Server Spoofing Vulnerability

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59233: Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.