Security
Headlines
HeadlinesLatestCVEs

Tag

#vulnerability

CVE-2025-53152: Desktop Windows Manager Remote Code Execution Vulnerability

Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally.

Microsoft Security Response Center
#vulnerability#windows#rce#auth#Desktop Windows Manager#Security Vulnerability
CVE-2025-47954: Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVE-2025-53156: Windows Storage Port Driver Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.

CVE-2025-53793: Azure Stack Hub Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** System internal configuration could be disclosed by this vulnerability.

CVE-2025-50165: Windows Graphics Component Remote Code Execution Vulnerability

**According to the CVSS metric, attack vector is (AV:N) and user interaction is none (UI:N). What does that mean for this vulnerability?** This can happen without user intervention. An attacker can use an uninitialized function pointer being called when decoding a JPEG image. This can be embedded in Office and 3rd party documents/files