CVE-2025-27730: Windows Digital Media Elevation of Privilege Vulnerability
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Browse CVE records published in April 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 3966 matching CVEs · Page 2 of 80.
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in Windows Shell allows an unauthorized attacker to execute code locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Published Apr 8, 2025 · Updated Aug 10, 2026
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published Apr 4, 2025 · Updated Aug 10, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published Apr 3, 2025 · Updated Aug 10, 2026
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Published Apr 8, 2025 · Updated Aug 10, 2026
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
Published Apr 8, 2025 · Updated Aug 10, 2026