Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows 10 Version 1507.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-64680HIGH | Windows DWM Core Library Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. CWE-122Dec 9, 2025 | CVSS7.8v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64679HIGH | Windows DWM Core Library Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. CWE-122Dec 9, 2025 | CVSS7.8v3.1 | EPSS0.459% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62209MEDIUM | Windows License Manager Information Disclosure VulnerabilityInsertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. CWE-532Nov 11, 2025 | CVSS5.5v3.1 | EPSS0.515% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62208MEDIUM | Windows License Manager Information Disclosure VulnerabilityInsertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. CWE-532Nov 11, 2025 | CVSS5.5v3.1 | EPSS0.515% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59278HIGH | Windows Authentication Elevation of Privilege VulnerabilityImproper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. CWE-1287Oct 14, 2025 | CVSS7.8v3.1 | EPSS0.255% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59275HIGH | Windows Authentication Elevation of Privilege VulnerabilityImproper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | CVSS7.8v3.1 | EPSS0.255% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59253MEDIUM | Windows Search Service Denial of Service VulnerabilityImproper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. CWE-284Oct 14, 2025 | CVSS5.5v3.1 | EPSS0.314% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59230HIGH | Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityImproper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. CWE-284Oct 14, 2025 | CVSS7.8v3.1 | EPSS2.58% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59244MEDIUM | NTLM Hash Disclosure Spoofing VulnerabilityExternal control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. CWE-73Oct 14, 2025 | CVSS6.5v3.1 | EPSS0.764% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59214MEDIUM | Microsoft Windows File Explorer Spoofing VulnerabilityExposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. CWE-200Oct 14, 2025 | CVSS6.5v3.1 | EPSS1.78% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59209MEDIUM | Windows Push Notification Information Disclosure VulnerabilityExposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. CWE-200Oct 14, 2025 | CVSS5.5v3.1 | EPSS0.436% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59208HIGH | Windows MapUrlToZone Information Disclosure VulnerabilityOut-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. CWE-125Oct 14, 2025 | CVSS7.1v3.1 | EPSS0.466% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59205HIGH | Windows Graphics Component Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. CWE-362Oct 14, 2025 | CVSS7.0v3.1 | EPSS0.185% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59203MEDIUM | Windows State Repository API Server File Information Disclosure VulnerabilityInsertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. CWE-532Oct 14, 2025 | CVSS5.5v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59198MEDIUM | Windows Search Service Denial of Service VulnerabilityImproper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. CWE-20Oct 14, 2025 | CVSS5.0v3.1 | EPSS0.442% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59197MEDIUM | Windows ETL Channel Information Disclosure VulnerabilityInsertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. CWE-532Oct 14, 2025 | CVSS5.5v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59192HIGH | Storport.sys Driver Elevation of Privilege VulnerabilityBuffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. CWE-126Oct 14, 2025 | CVSS7.8v3.1 | EPSS0.274% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59190MEDIUM | Windows Search Service Denial of Service VulnerabilityImproper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. CWE-20Oct 14, 2025 | CVSS5.5v3.1 | EPSS0.467% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59187HIGH | Windows Kernel Elevation of Privilege VulnerabilityImproper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS7.8v3.1 | EPSS0.285% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58739MEDIUM | Microsoft Windows File Explorer Spoofing VulnerabilityExposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. CWE-200Oct 14, 2025 | CVSS6.5v3.1 | EPSS0.764% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58738HIGH | Inbox COM Objects (Global Memory) Remote Code Execution VulnerabilityUse after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.0v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58736HIGH | Inbox COM Objects (Global Memory) Remote Code Execution VulnerabilityUse after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.0v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58734HIGH | Inbox COM Objects (Global Memory) Remote Code Execution VulnerabilityUse after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.0v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58733HIGH | Inbox COM Objects (Global Memory) Remote Code Execution VulnerabilityUse after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.0v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58730HIGH | Inbox COM Objects (Global Memory) Remote Code Execution VulnerabilityUse after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. CWE-416Oct 14, 2025 | CVSS7.0v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |