Vulnerabilities
Vulnerable Software
Microsoft:  >> Windows Server 2025  Security Vulnerabilities
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
CVSS Score
6.5
EPSS Score
0.013
Published
2026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.007
Published
2026-01-13
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2026-01-13
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.
CVSS Score
6.2
EPSS Score
0.006
Published
2026-01-13
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
CVSS Score
7.7
EPSS Score
0.005
Published
2026-01-13
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.006
Published
2026-01-13
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.005
Published
2026-01-13
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.024
Published
2026-01-13
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.004
Published
2026-01-13
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.033
Published
2026-01-13


Contact Us

Shodan ® - All rights reserved