Skip to main content

Vendor/product archive

microsoft / windows_11_25h2 CVEs

Beta · best-effort

1,014 CVEs tagged to microsoft / windows_11_25h218 Critical, 754 High, 236 Medium, 6 Low, 0 Unrated.

CVE-2026-20867

Published Jan 13, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges loca…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20866

Published Jan 13, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges loca…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20865

Published Jan 13, 2026

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20864

Published Jan 13, 2026

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-20862

Published Jan 13, 2026

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-20861

Published Jan 13, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges loca…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20858

Published Jan 13, 2026

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20857

Published Jan 13, 2026

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20848

Published Jan 13, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a networ…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 776-800 of 1,014 CVEsPage 32 of 41