CWE-822

Untrusted Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

212 vulnerabilities with CWE-822
CVE-2025-54905 HIGH
Microsoft Office Word - Info Disclosure
CVSS 7.1
CVE-2025-54114 HIGH
Windows - Privilege Escalation via Race Condition in Connected Devices Platform Service
CVSS 7.0
CVE-2025-53801 HIGH
Windows 10 1507-22H2, Windows 11 22H2-23H2, Windows Server 2016-2022 - Untrusted Pointer Dereference
CVSS 7.8
CVE-2025-55230 HIGH
Windows MBT Transport < - Privilege Escalation
CVSS 7.8
CVE-2025-50165 CRITICAL
Windows 11 24H2 and Windows Server 2025 < 10.0.26100.4851 - Remote Code Execution via Untrusted Pointer Dereference
CVSS 9.8
CVE-2025-20090 MEDIUM
Intel(R) QuickAssist Technology <2.5.0 - DoS
CVSS 5.5
CVE-2025-27069 HIGH
Qualcomm FastConnect and WCD/WSA Firmware - Memory Corruption via DDI Command
CVSS 7.8
CVE-2025-49689 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Local Privilege Escalation via VHDX Integer Overflow
CVSS 7.8
CVE-2025-49661 HIGH
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
CVE-2025-47985 HIGH
Windows Event Tracing - Privilege Escalation
CVSS 7.8
CVE-2025-47982 HIGH
Windows Storage VSP Driver - Privilege Escalation
CVSS 7.8
CVE-2025-21486 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2025-20018 HIGH
Intel(R) Graphics Drivers - Privilege Escalation
CVSS 8.4
CVE-2025-30381 HIGH
Microsoft Office Excel - Code Injection
CVSS 7.8
CVE-2025-29812 HIGH
Microsoft Windows Kernel Untrusted Pointer Dereference - Privilege Escalation
CVSS 7.8
CVE-2025-27747 HIGH
Microsoft 365 Apps and Office - Use-After-Free
CVSS 7.8
CVE-2025-27739 HIGH
Microsoft Windows Kernel Untrusted Pointer Dereference - Privilege Escalation
CVSS 7.8
CVE-2025-22464 MEDIUM
Ivanti Endpoint Manager <2024 SU1, <2022 SU7 - Memory Corruption
CVSS 6.1
CVE-2025-24084 HIGH
Windows 11 22H2 < 10.0.22621.5039 - Unauthenticated Untrusted Pointer Dereference in Windows Subsystem for Linux
CVSS 8.4
CVE-2025-24083 HIGH
Microsoft 365 Apps and Office - Unauthenticated Remote Code Execution via Untrusted Pointer Dereference
CVSS 7.8
CVE-2025-21381 HIGH
Microsoft Excel - Remote Code Execution via Untrusted Pointer Dereference
CVSS 7.8
CVE-2025-21358 HIGH
Windows Core Messaging - Privilege Escalation
CVSS 7.8
CVE-2025-21363 HIGH
Microsoft 365 Apps and Office LTSC - Remote Code Execution via Untrusted Pointer Dereference
CVSS 7.8
CVE-2025-21354 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Untrusted Pointer Dereference
CVSS 8.4
CVE-2024-36352 HIGH
AMD Graphics Driver - Memory Corruption
CVSS 8.4
Details
Vulnerabilities 212