Autor: Peter Leibling

CVE-2025-62461 Windows Projected File System Elevation of Privilege Vulnerability

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-64667 Microsoft Exchange Server Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-62466 Windows Client-Side Caching Elevation of Privilege Vulnerability

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2025-64658 Windows File Explorer Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2025-62458 Win32k Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.

CVE-2025-62470 Windows Common Log File System Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-62472 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2025-62469 Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2025-62552 Microsoft Access Remote Code Execution Vulnerability

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

CVE-2025-64673 Windows Storage VSP Driver Elevation of Privilege Vulnerability

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.