Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2025-33056: Windows Local Security Authority (LSA) Denial of Service Vulnerability

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Microsoft Security Response Center
#vulnerability#windows#microsoft#dos#auth#Microsoft Local Security Authority Server (lsasrv)#Security Vulnerability
CVE-2025-47956: Windows Security App Spoofing Vulnerability

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

CVE-2025-47172: Microsoft SharePoint Server Remote Code Execution Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.