Security Vulnerabilities
- CVEs Published In April 2025
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.