AMD: CVE-2025-54518 CPU OP Cache Corruption
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
.NET Core Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
.NET Framework Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Active Directory Security Feature Bypass Vulnerability
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
.NET Framework Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.