Kategorie: Allgemein

CVE-2025-62469 Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2025-62557 Microsoft Office Remote Code Execution Vulnerability

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-62563 Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-62561 Microsoft Excel Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-62573 DirectX Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2025-62571 Windows Installer Elevation of Privilege Vulnerability

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2025-64666 Microsoft Exchange Server Elevation of Privilege Vulnerability

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CVE-2025-62473 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

[UPDATE] [hoch] Siemens SICAM: Mehrere Schwachstellen

Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.

[UPDATE] [hoch] Google Cloud Platform: Schwachstelle ermöglicht Codeausführung

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Google Cloud Platform ausnutzen, um beliebigen Programmcode auszuführen.