Autor: Peter Leibling

CVE-2025-26671 Windows Remote Desktop Services Remote Code Execution Vulnerability

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2025-20570 Visual Studio Code Elevation of Privilege Vulnerability

Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

CVE-2025-27731 Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability

Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

CVE-2025-27729 Windows Shell Remote Code Execution Vulnerability

Use after free in Windows Shell allows an unauthorized attacker to execute code locally.

CVE-2025-27490 Windows Bluetooth Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2025-26680 Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

CVE-2025-27477 Windows Telephony Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

HCL: Sicherheitslücken in BigFix, DevOps und mehr Produkten

HCL warnt vor teils kritischen Sicherheitslücken. Updates stehen für BigFix, DevOps, Traveler und Connections bereit.

[NEU] [mittel] ESET NOD32 Antivirus, Endpoint Security and Server Security: Schwachstelle ermöglicht Codeausführung

Ein lokaler Angreifer kann eine Schwachstelle in ESET NOD32 Antivirus ausnutzen, um beliebigen Programmcode auszuführen.

[NEU] [mittel] Siemens SIMATIC S7: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Siemens SIMATIC S7 ausnutzen, um einen Denial of Service Angriff durchzuführen.