Security Vulnerabilities
- CVEs Published In October 2025
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.