Autor: Peter Leibling

CVE-2025-59240 Microsoft Excel Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-62215 Windows Kernel Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2025-60710 Host Process for Windows Tasks Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2025-62222 Agentic AI and Visual Studio Code Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command (‚command injection‘) in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.

CVE-2025-60721 Windows Administrator Protection Elevation of Privilege Vulnerability

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

CVE-2025-59515 Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

CVE-2025-60709 Windows Common Log File System Driver Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-62211 Dynamics 365 Field Service (online) Spoofing Vulnerability

Improper neutralization of input during web page generation (‚cross-site scripting‘) in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

CVE-2025-62203 Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-60708 Storvsp.sys Driver Denial of Service Vulnerability

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.