Aggregator
CVE-2025-21373 | Microsoft Windows up to Server 2025 Installer link following
1 year 5 months ago
A vulnerability was found in Microsoft Windows and classified as critical. This issue affects some unknown processing of the component Installer. The manipulation leads to link following.
The identification of this vulnerability is CVE-2025-21373. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21358 | Microsoft Windows up to Server 2025 Core Messaging untrusted pointer dereference
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. This issue affects some unknown processing of the component Core Messaging. The manipulation leads to untrusted pointer dereference.
The identification of this vulnerability is CVE-2025-21358. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21371 | Microsoft Windows up to Server 2025 Telephony Service heap-based overflow (Nessus ID 216140)
1 year 5 months ago
A vulnerability has been found in Microsoft Windows and classified as critical. This vulnerability affects unknown code of the component Telephony Service. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2025-21371. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21369 | Microsoft Windows up to Server 2025 Digest Authentication heap-based overflow (Nessus ID 216140)
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. This affects an unknown part of the component Digest Authentication. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-21369. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21352 | Microsoft Windows up to Server 2025 resource consumption
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to resource consumption.
This vulnerability was named CVE-2025-21352. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21368 | Microsoft Windows up to Server 2025 Digest Authentication heap-based overflow (Nessus ID 216140)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows. Affected by this issue is some unknown functionality of the component Digest Authentication. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2025-21368. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21351 | Microsoft Windows up to Server 2025 Active Directory Domain Services API resource consumption
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. This affects an unknown part of the component Active Directory Domain Services API. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2025-21351. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21367 | Microsoft Windows up to Server 2025 Win32 Kernel Subsystem use after free
1 year 5 months ago
A vulnerability classified as critical was found in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Win32 Kernel Subsystem. The manipulation leads to use after free.
This vulnerability is known as CVE-2025-21367. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21359 | Microsoft Windows up to Server 2025 Kernel access control
1 year 5 months ago
A vulnerability classified as critical has been found in Microsoft Windows. Affected is an unknown function of the component Kernel. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-21359. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21358 | Microsoft Windows up to Server 2025 Core Messaging untrusted pointer dereference
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. This issue affects some unknown processing of the component Core Messaging. The manipulation leads to untrusted pointer dereference.
The identification of this vulnerability is CVE-2025-21358. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21352 | Microsoft Windows up to Server 2025 resource consumption
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to resource consumption.
This vulnerability was named CVE-2025-21352. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21351 | Microsoft Windows up to Server 2025 Active Directory Domain Services API resource consumption
1 year 5 months ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. This affects an unknown part of the component Active Directory Domain Services API. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2025-21351. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21350 | Microsoft Windows up to Server 2025 Kerberos denial of service
1 year 5 months ago
A vulnerability was found in Microsoft Windows and classified as problematic. Affected by this issue is some unknown functionality of the component Kerberos. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2025-21350. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21349 | Microsoft Windows up to Server 2025 Remote Desktop Configuration Service improper authentication
1 year 5 months ago
A vulnerability has been found in Microsoft Windows and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Remote Desktop Configuration Service. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2025-21349. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-21347 | Microsoft Windows up to Server 2025 Deployment Services link following
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Microsoft Windows. Affected is an unknown function of the component Deployment Services. The manipulation leads to link following.
This vulnerability is traded as CVE-2025-21347. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
SAP security advisory – February 2025 monthly rollup (AV25-073)
1 year 5 months ago
Canadian Centre for Cyber Security
Fortune 500 Employees’ Credentials Under Siege
1 year 5 months ago
1 in 10 Fortune 500 employees had their credentials exposed. Each compromised account was found an average of 5.7 times.
The post Fortune 500 Employees’ Credentials Under Siege appeared first on Security Boulevard.
Enzoic
xss-labs 靶场详细攻略(附常用payload)
1 year 5 months ago
本篇文章非常详细的讲述了xss-labs的过关流程,并且附上大多数关卡的源码来讲解作者考察的知识点和原理。
CVE-2025-21183 | Microsoft Windows 11 24H2/Server 2025 Resilient File System Deduplication Service double free
1 year 5 months ago
A vulnerability was found in Microsoft Windows 11 24H2/Server 2025 and classified as critical. Affected by this issue is some unknown functionality of the component Resilient File System Deduplication Service. The manipulation leads to double free.
This vulnerability is handled as CVE-2025-21183. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com