Autor: Peter Leibling

CVE-2025-59184 Storage Spaces Direct Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.

CVE-2025-58736 Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

CVE-2025-55698 DirectX Graphics Kernel Denial of Service Vulnerability

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

CVE-2025-59221 Microsoft Word Remote Code Execution Vulnerability

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-59208 Windows MapUrlToZone Information Disclosure Vulnerability

Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

CVE-2025-59241 Windows Health and Optimized Experiences Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.

CVE-2025-55697 Azure Local Elevation of Privilege Vulnerability

Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

CVE-2025-59225 Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59201 Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability

Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

CVE-2025-59285 Azure Monitor Agent Elevation of Privilege Vulnerability

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.