Security Vulnerabilities
- CVEs Published In November 2025
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.