Microsoft Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.