Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2025-29824: Windows Common Log File System Driver Elevation of Privilege Vulnerability

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Microsoft Security Response Center
#vulnerability#windows#auth#Windows Common Log File System Driver#Security Vulnerability
CVE-2025-21204: Windows Process Activation Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2025-21203: Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

**According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?** This attack requires an admin user on the client to connect to a malicious server and then take specific actions which could result in information disclosure.

CVE-2025-27742: NTFS Information Disclosure Vulnerability

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.