4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-55313
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.

CVE-2025-66494
Foxit PDF Reader Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacker to execute arbitrary code.

CVE-2025-1683
1E Client Windows
7.8
HIGH
EPSS
0.2%
2025 CWE-59 1 PoC

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.

CVE-2025-47987
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
5.5%
2025 CWE-122 1 PoC

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.

CVE-2025-24985
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.7%
2025 CWE-190 3 PoCs

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

CVE-2025-55314
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2025-21204
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
7.3%
2025 CWE-59 2 PoCs

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVE-2025-55312
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2025-32706
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
1.3%
2025 CWE-20 2 PoCs

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-57836
Software Genérico Windows
7.8
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.

CVE-2025-32709
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-416 1 PoC

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-53841
Guardicore Platform Agent Windows
7.8
HIGH
EPSS
0.0%
2025 CWE-829 1 PoC

The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to create a crafted "openssl.cnf" file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore

CVE-2025-21420
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
41.5%
2025 CWE-59 2 PoCs

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

CVE-2025-60710
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
29.7%
2025 CWE-59 2 PoCs

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2025-59230
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
3.7%
2025 CWE-284 2 PoCs

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2025-24864
RemoteView Agent (for Windows) Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.

CVE-2025-60707
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-416 2 PoCs

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

CVE-2025-29824
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.3%
2025 CWE-416 2 PoCs

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2025-55230
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-822 1 PoC

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.