Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

CVE-2025-53717: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Microsoft Security Response Center
#vulnerability#windows#auth#Windows Virtualization-Based Security (VBS) Enclave#Security Vulnerability
CVE-2025-25004: PowerShell Elevation of Privilege Vulnerability

**What privileges could be gained by an attacker who successfully exploited the vulnerability?** An attacker who successfully exploited this vulnerability could create, modify, or delete files in the security context of the "NT AUTHORITY\\SYSTEM" account.

CVE-2025-48813: Virtual Secure Mode Spoofing Vulnerability

Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

CVE-2025-59502: Remote Procedure Call Denial of Service Vulnerability

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

CVE-2025-53139: Windows Hello Security Feature Bypass Vulnerability

Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.