Autor: Peter Leibling

CVE-2025-54912 Windows BitLocker Elevation of Privilege Vulnerability

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

CVE-2025-54917 MapUrlToZone Security Feature Bypass Vulnerability

Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

CVE-2025-54116 Windows MultiPoint Services Elevation of Privilege Vulnerability

Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

CVE-2025-54101 Windows SMB Client Remote Code Execution Vulnerability

Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

CVE-2025-54899 Microsoft Excel Remote Code Execution Vulnerability

Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-55317 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

CVE-2025-49692 Azure Connected Machine Agent Elevation of Privilege Vulnerability

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

CVE-2025-54096 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVE-2025-54897 Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2025-54895 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.