Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2025-24065: Windows Storage Management Provider Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** The type of information that could be disclosed if an attacker successfully exploited this vulnerability is an out of bounds read in the caller's address space memory.

Microsoft Security Response Center
#vulnerability#windows#Windows Storage Management Provider#Security Vulnerability
CVE-2025-47969: Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

CVE-2025-47962: Windows SDK Elevation of Privilege Vulnerability

**Is there more information that is available on Windows SDK?** Yes. Please see: Windows SDK - Windows app development which explains the Windows SDK and advises how to install and maintain the product.

CVE-2025-33052: Windows DWM Core Library Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized stack memory.

CVE-2025-47160: Windows Shortcut Files Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

CVE-2025-33075: Windows Installer Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.