Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2025-47997: Microsoft SQL Server Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.

Microsoft Security Response Center
#sql#vulnerability#microsoft#SQL Server#Security Vulnerability
CVE-2025-55317: Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Microsoft Teams allows an authorized attacker to elevate privileges locally.

CVE-2025-55243: Microsoft OfficePlus Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-54905: Microsoft Word Information Disclosure Vulnerability

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.