windows_server_2025 vulnerabilities
CVEs whose affected-version data names the windows_server_2025 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
1586 CVEsRSS
CVE-2026-65672High· 7.8Remote Access API Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65671High· 7.8Remote Access API Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-65662Medium· 5.5Windows GDI Information Disclosure Vulnerability
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-68820High· 7.0CISA KEV0dayPoCWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-68819Medium· 5.9Windows Network File System Denial of Service Vulnerability
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
CVE-2026-61359High· 7.8Windows Storage Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-61357High· 7.8Application Information Services Elevation of Privilege Vulnerability
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61355High· 7.8Windows Sensor Data Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-59126High· 7.0Windows Event Logging Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62733High· 7.8Windows Win32k Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62728High· 7.0Windows Common Log File System Driver Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62726High· 7.0Windows Telephony Service Elevation of Privilege Vulnerability
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62725High· 7.0Windows Telephony Service Elevation of Privilege Vulnerability
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62721High· 7.8Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
CVE-2026-62720Medium· 6.5Windows DHCP Server Information Disclosure Vulnerability
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62708Medium· 6.4Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-61938High· 7.0Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-61929High· 7.0Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62823High· 8.8Windows DHCP Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62814Medium· 6.5Windows DHCP Server Information Disclosure Vulnerability
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62807High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62803High· 7.8Windows DHCP Server Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62800High· 8.8Windows SMBv3 Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-62793Medium· 5.5Windows NTFS Information Disclosure Vulnerability
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62790High· 8.8Windows SMBv3 Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-62788High· 7.0Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62786Medium· 5.5Win32k Information Disclosure Vulnerability
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62782Medium· 6.5Windows SMB Client Information Disclosure Vulnerability
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-62781High· 8.1RPC Runtime Library Remote Code Execution Vulnerability
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
CVE-2026-62780High· 7.0Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.