BlackTreeCVE IntelligenceMicrosoft · KB5050021
Linked CVE review
Deploy Microsoft Windows security update KB5050021
- Linked CVEs
- 119
- Confirmed exploited
- 3
- PoC or lab evidence
- 2
- Maximum CVSS
- 9.8
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2025-21333 Immediate evidence Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow VulnerabilityMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. | 7.8 · CVSS 3.1 · HighSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised. | EPSS: 9.99% · 95.5th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Patch nowCISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21334 Immediate evidence Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free VulnerabilityMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | 7.8 · CVSS 3.1 · HighSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.56% · 74.5th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Patch nowCISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21335 Immediate evidence Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free VulnerabilityMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | 7.8 · CVSS 3.1 · HighSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.39% · 71.5th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Patch nowCISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21298 PoC or lab evidence Windows OLE Remote Code Execution VulnerabilityWindows OLE Remote Code Execution Vulnerability | 9.8 · CVSS 3.1 · CriticalSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedCISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material. | EPSS: 80.9% · 99.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21307 Critical technical severity Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | 9.8 · CVSS 3.1 · CriticalSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.91% · 79.1th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21285 Elevated EPSS forecast Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 55.7% · 99.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21277 Elevated EPSS forecast Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 38.6% · 98.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21293 Elevated EPSS forecast Active Directory Domain Services Elevation of Privilege VulnerabilityActive Directory Domain Services Elevation of Privilege Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 19.0% · 97.2th percentileForecast date: 2026-10-07NETWORK · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21230 Scheduled assessment Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.69% · 85.4th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21231 Scheduled assessment IP Helper Denial of Service VulnerabilityIP Helper Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.59% · 84.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21251 Scheduled assessment Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.59% · 84.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21300 Scheduled assessment Windows Universal Plug and Play (UPnP) Device Host Denial of Service VulnerabilityWindows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.53% · 84.4th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21276 Scheduled assessment Windows MapUrlToZone Denial of Service VulnerabilityWindows MapUrlToZone Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.42% · 83.7th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21270 Scheduled assessment Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.40% · 83.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21289 Scheduled assessment Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.40% · 83.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21290 Scheduled assessment Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityMicrosoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.40% · 83.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21299 Scheduled assessment Windows Kerberos Security Feature Bypass VulnerabilityWindows Kerberos Security Feature Bypass Vulnerability | 7.1 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.21% · 82.1th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21220 Scheduled assessment Microsoft Message Queuing Information Disclosure VulnerabilityMicrosoft Message Queuing Information Disclosure Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.15% · 81.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21207 Scheduled assessment Windows Connected Devices Platform Service (Cdpsvc) Denial of Service VulnerabilityWindows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.11% · 81.2th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21330 Scheduled assessment Windows Remote Desktop Services Denial of Service VulnerabilityWindows Remote Desktop Services Denial of Service Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.96% · 79.7th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21389 Scheduled assessment Windows Universal Plug and Play (UPnP) Device Host Denial of Service VulnerabilityUncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.94% · 79.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21224 Scheduled assessment Windows Line Printer Daemon (LPD) Service Remote Code Execution VulnerabilityWindows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 8.1 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.91% · 79.1th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21233 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21236 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21237 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21238 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21240 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21243 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21244 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21245 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21246 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21250 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.69% · 76.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21223 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.62% · 75.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21295 Scheduled assessment SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution VulnerabilitySPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 8.1 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.61% · 75.2th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21239 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.49% · 73.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21241 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.49% · 73.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21248 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.49% · 73.3th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21252 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.42% · 71.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21302 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.42% · 71.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21303 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.42% · 71.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21305 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.42% · 71.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21306 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.42% · 71.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21291 Scheduled assessment Windows Direct Show Remote Code Execution VulnerabilityWindows Direct Show Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.40% · 71.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21343 Scheduled assessment Windows Web Threat Defense User Service Information Disclosure VulnerabilityWindows Web Threat Defense User Service Information Disclosure Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.35% · 70.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21266 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21273 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21282 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21286 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.27% · 68.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21294 Scheduled assessment Microsoft Digest Authentication Remote Code Execution VulnerabilityMicrosoft Digest Authentication Remote Code Execution Vulnerability | 8.1 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.21% · 67.5th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21417 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.17% · 66.4th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21339 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.11% · 64.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21409 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.11% · 64.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21411 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.11% · 64.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21413 Scheduled assessment Windows Telephony Service Remote Code Execution VulnerabilityWindows Telephony Service Remote Code Execution Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.11% · 64.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21331 Scheduled assessment Windows Installer Elevation of Privilege VulnerabilityWindows Installer Elevation of Privilege Vulnerability | 7.3 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.02% · 62.2th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · REQUIRED user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21292 Scheduled assessment Windows Search Service Elevation of Privilege VulnerabilityWindows Search Service Elevation of Privilege Vulnerability | 8.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.1th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21296 Scheduled assessment BranchCache Remote Code Execution VulnerabilityBranchCache Remote Code Execution Vulnerability | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.78% · 54.5th percentileForecast date: 2026-10-07ADJACENT · HIGH complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21275 Scheduled assessment Windows App Package Installer Elevation of Privilege VulnerabilityWindows App Package Installer Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.62% · 48.0th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21281 Scheduled assessment Microsoft COM for Windows Elevation of Privilege VulnerabilityMicrosoft COM for Windows Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.60% · 47.3th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21234 Scheduled assessment Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityWindows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.59% · 46.6th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21235 Scheduled assessment Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityWindows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.59% · 46.6th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21378 Scheduled assessment Windows CSC Service Elevation of Privilege VulnerabilityWindows CSC Service Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.56% · 45.1th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21287 Scheduled assessment Windows Installer Elevation of Privilege VulnerabilityWindows Installer Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.55% · 44.2th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21382 Scheduled assessment Windows Graphics Component Elevation of Privilege VulnerabilityWindows Graphics Component Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.50% · 41.1th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21338 Scheduled assessment GDI+ Remote Code Execution VulnerabilityGDI+ Remote Code Execution Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.48% · 39.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21370 Scheduled assessment Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityWindows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | 7.8 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.47% · 38.7th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21269 Scheduled assessment Windows HTML Platforms Security Feature Bypass VulnerabilityWindows HTML Platforms Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 4.59% · 91.4th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21219 Scheduled assessment MapUrlToZone Security Feature Bypass VulnerabilityMapUrlToZone Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 3.02% · 87.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21189 Scheduled assessment MapUrlToZone Security Feature Bypass VulnerabilityMapUrlToZone Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.97% · 86.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21308 Scheduled assessment Windows Themes Spoofing VulnerabilityWindows Themes Spoofing Vulnerability | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 2.21% · 82.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21268 Scheduled assessment MapUrlToZone Security Feature Bypass VulnerabilityMapUrlToZone Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.99% · 80.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21217 Scheduled assessment Windows NTLM Spoofing VulnerabilityWindows NTLM Spoofing Vulnerability | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.95% · 79.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21242 Scheduled assessment Windows Kerberos Information Disclosure VulnerabilityWindows Kerberos Information Disclosure Vulnerability | 5.9 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.65% · 75.7th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21301 Scheduled assessment Windows Geolocation Service Information Disclosure VulnerabilityWindows Geolocation Service Information Disclosure Vulnerability | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.56% · 74.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21328 Scheduled assessment MapUrlToZone Security Feature Bypass VulnerabilityMapUrlToZone Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.52% · 73.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21329 Scheduled assessment MapUrlToZone Security Feature Bypass VulnerabilityMapUrlToZone Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.52% · 73.8th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21332 Scheduled assessment MapUrlToZone Security Feature Bypass VulnerabilityMapUrlToZone Security Feature Bypass Vulnerability | 4.3 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.47% · 73.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21314 Scheduled assessment Windows SmartScreen Spoofing VulnerabilityWindows SmartScreen Spoofing Vulnerability | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.42% · 72.0th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21210 Scheduled assessment Windows BitLocker Information Disclosure VulnerabilityWindows BitLocker Information Disclosure Vulnerability | 4.2 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.14% · 65.6th percentileForecast date: 2026-10-07PHYSICAL · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21316 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.93% · 59.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21318 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.93% · 59.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21319 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.93% · 59.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21320 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.93% · 59.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21321 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.93% · 59.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21202 Scheduled assessment Windows Recovery Environment Agent Elevation of Privilege VulnerabilityWindows Recovery Environment Agent Elevation of Privilege Vulnerability | 6.1 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.88% · 57.8th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21226 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.87% · 57.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21317 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.85% · 56.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21323 Scheduled assessment Windows Kernel Memory Information Disclosure VulnerabilityWindows Kernel Memory Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.85% · 56.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21227 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21228 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21229 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21232 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21249 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21255 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21256 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21258 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21260 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21310 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21324 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21215 Scheduled assessment Secure Boot Security Feature Bypass VulnerabilitySecure Boot Security Feature Bypass Vulnerability | 4.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.82% · 55.8th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21274 Scheduled assessment Windows Event Tracing Denial of Service VulnerabilityWindows Event Tracing Denial of Service Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.78% · 54.7th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21211 Scheduled assessment Secure Boot Security Feature Bypass VulnerabilitySecure Boot Security Feature Bypass Vulnerability | 6.8 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.77% · 54.3th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21261 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.76% · 53.9th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21263 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.76% · 53.9th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21265 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.76% · 53.9th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21327 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.76% · 53.9th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21257 Scheduled assessment Windows WLAN AutoConfig Service Information Disclosure VulnerabilityWindows WLAN AutoConfig Service Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.73% · 52.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21213 Scheduled assessment Secure Boot Security Feature Bypass VulnerabilitySecure Boot Security Feature Bypass Vulnerability | 4.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.72% · 52.5th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21312 Scheduled assessment Windows Smart Card Reader Information Disclosure VulnerabilityWindows Smart Card Reader Information Disclosure Vulnerability | 2.4 · CVSS 3.1 · LowSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.72% · 52.4th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21214 Scheduled assessment Windows BitLocker Information Disclosure VulnerabilityWindows BitLocker Information Disclosure Vulnerability | 4.2 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.71% · 52.2th percentileForecast date: 2026-10-07PHYSICAL · HIGH complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21272 Scheduled assessment Windows COM Server Information Disclosure VulnerabilityWindows COM Server Information Disclosure Vulnerability | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.71% · 51.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21288 Scheduled assessment Windows COM Server Information Disclosure VulnerabilityWindows COM Server Information Disclosure Vulnerability | 6.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.71% · 51.9th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21341 Scheduled assessment Windows Digital Media Elevation of Privilege VulnerabilityWindows Digital Media Elevation of Privilege Vulnerability | 6.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.70% · 51.6th percentileForecast date: 2026-10-07PHYSICAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21280 Scheduled assessment Windows Virtual Trusted Platform Module Denial of Service VulnerabilityWindows Virtual Trusted Platform Module Denial of Service Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.67% · 50.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21284 Scheduled assessment Windows Virtual Trusted Platform Module Denial of Service VulnerabilityWindows Virtual Trusted Platform Module Denial of Service Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.67% · 50.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21336 Scheduled assessment Windows Cryptographic Information Disclosure VulnerabilityWindows Cryptographic Information Disclosure Vulnerability | 5.6 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.63% · 48.6th percentileForecast date: 2026-10-07LOCAL · HIGH complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21374 Scheduled assessment Windows CSC Service Information Disclosure VulnerabilityWindows CSC Service Information Disclosure Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.59% · 46.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21278 Scheduled assessment Windows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityWindows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 6.2 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.57% · 45.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · NONE privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |
CVE-2025-21340 Scheduled assessment Windows Virtualization-Based Security (VBS) Security Feature Bypass VulnerabilityWindows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | 5.5 · CVSS 3.1 · MediumSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.45% · 37.3th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interaction | ScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. |