Autor: Peter Leibling

[NEU] [mittel] Fortinet FortiWeb: Mehrere Schwachstellen

Ein entfernter Angreifer kann mehrere Schwachstellen in Fortinet FortiWeb ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Daten zu manipulieren.

[UPDATE] [mittel] AMD Radeon: Schwachstelle ermöglicht Offenlegung von Informationen

Ein lokaler Angreifer kann eine Schwachstelle in AMD Radeon und AMD Prozessor ausnutzen, um Informationen offenzulegen.

[UPDATE] [hoch] Linux Kernel: Schwachstelle ermöglicht Privilegieneskalation

Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um seine Privilegien zu erhöhen.

CVE-2025-24061 Windows Mark of the Web Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24049 Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command (‚command injection‘) in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.

CVE-2025-24043 WinDbg Remote Code Execution Vulnerability

Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.

CVE-2025-24076 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2025-24055 Windows USB Video Class System Driver Information Disclosure Vulnerability

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.

CVE-2025-24044 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.