Autor: Peter Leibling

CVE-2025-59208 Windows MapUrlToZone Information Disclosure Vulnerability

Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

CVE-2025-59241 Windows Health and Optimized Experiences Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.

CVE-2025-55697 Azure Local Elevation of Privilege Vulnerability

Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

CVE-2025-59225 Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59201 Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability

Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

CVE-2025-55315 ASP.NET Security Feature Bypass Vulnerability

Inconsistent interpretation of http requests (‚http request/response smuggling‘) in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CVE-2025-59238 Microsoft PowerPoint Remote Code Execution Vulnerability

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-55339 Windows Network Driver Interface Specification Driver Elevation of Privilege Vulnerability

Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

CVE-2025-59285 Azure Monitor Agent Elevation of Privilege Vulnerability

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen

Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um Daten zu manipulieren oder einen Denial of Service herbeizuführen.