Live
CVE-2025-59529: Critical Avahi mDNS DoS Vulnerability Threatens Local Networks·MSFT +2.1%GRUB2 CVE-2025-61664: Critical Bootloader Vulnerability Threatens Windows Dual-Boot Systems·NVDA +0.2%Windows camsvc Race Condition Exploited for SYSTEM Access: Urgent Patch Deployed·GOOGL +1.7%Windows Firewall’s Memory Misfire: How CVE-2025-54094 Opens a Door to SYSTEM Privileges·AMZN +1.1%Microsoft Issues Urgent Fix for Windows Defender Firewall Type-Confusion EoP (CVE-2025-54104)·MSFT +2.1%Microsoft Patches Windows Imaging Component Flaw That Could Leak Sensitive Data Through Crafted Images·NVDA +0.2%Windows NEGOEX Integer Overflow Lets Attackers Escalate to SYSTEM—Patch Now·GOOGL +1.7%Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control·AMZN +1.1%CVE-2025-59529: Critical Avahi mDNS DoS Vulnerability Threatens Local Networks·MSFT +2.1%GRUB2 CVE-2025-61664: Critical Bootloader Vulnerability Threatens Windows Dual-Boot Systems·NVDA +0.2%Windows camsvc Race Condition Exploited for SYSTEM Access: Urgent Patch Deployed·GOOGL +1.7%Windows Firewall’s Memory Misfire: How CVE-2025-54094 Opens a Door to SYSTEM Privileges·AMZN +1.1%Microsoft Issues Urgent Fix for Windows Defender Firewall Type-Confusion EoP (CVE-2025-54104)·MSFT +2.1%Microsoft Patches Windows Imaging Component Flaw That Could Leak Sensitive Data Through Crafted Images·NVDA +0.2%Windows NEGOEX Integer Overflow Lets Attackers Escalate to SYSTEM—Patch Now·GOOGL +1.7%Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control·AMZN +1.1%

Local Attack

The latest Local Attack coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 9:58 PM
Latest Most Read Breaking
Sort
Avahi · Denial Of Service

CVE-2025-59529: Critical Avahi mDNS DoS Vulnerability Threatens Local Networks

A newly disclosed vulnerability in the Avahi mDNS/DNS-SD implementation—tracked as CVE-2025-59529—has security researchers and system administrators on high alert. This critical flaw allows...

Advertisement
Applocker · Cve-2025-54104

Microsoft Issues Urgent Fix for Windows Defender Firewall Type-Confusion EoP (CVE-2025-54104)

Microsoft has confirmed a critical elevation-of-privilege vulnerability in the Windows Defender Firewall Service (MpsSvc) that could enable an attacker with local access to escalate to SYSTEM-level...

SE Security Desk·44w ago
Cve-2025-47980 · Cybersecurity

Microsoft Patches Windows Imaging Component Flaw That Could Leak Sensitive Data Through Crafted Images

A critical information disclosure vulnerability in the Windows Imaging Component (WIC) was among the top fixes delivered in Microsoft’s July 2025 Patch Tuesday updates. Tracked as CVE-2025-47980,...

SE Security Desk·44w ago
Authentication · Cve-2025-54895

Windows NEGOEX Integer Overflow Lets Attackers Escalate to SYSTEM—Patch Now

Microsoft has released a security update to plug a critical elevation-of-privilege hole in the Windows NEGOEX authentication mechanism. Tracked as CVE-2025-54895, the flaw stems from an integer...

SE Security Desk·44w ago
Cdpsvc · Cve-2025-54102

Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control

A high-severity vulnerability in the Windows Connected Devices Platform Service (CDPSvc), cataloged as CVE-2025-54102, can be exploited by a low-privileged local attacker to gain NT AUTHORITY\SYSTEM...

SE Security Desk·44w ago
Cve-2025-40584 · Cwe-611

CVE-2025-40584: Siemens SIMOTION and SINAMICS Tools Vulnerable to XXE File Disclosure, Some Left Unpatched

Siemens has acknowledged a critical XML External Entity (XXE) vulnerability—tracked as CVE-2025-40584—affecting multiple versions of its SIMOTION SCOUT, SIMOTION SCOUT TIA, and SINAMICS STARTER...

SE Security Desk·48w ago
Cisa · Cve-2025-7532

Rockwell Automation Patches FactoryTalk Action Manager Vulnerability That Broadcasts API Tokens

Rockwell Automation has confirmed a high-severity information disclosure vulnerability in its FactoryTalk Action Manager software that broadcasts reusable API tokens over local WebSocket channels,...

SE Security Desk·48w ago
Cve-2025-53726 · Cyber Hygiene

Microsoft Warns of CVE-2025-53726: Windows Push Notification Flaw Grants SYSTEM Access to Local Attackers

Microsoft has published a high-priority security advisory for CVE-2025-53726, a type-confusion vulnerability in the Windows Push Notifications component that allows an authenticated local attacker to...

SE Security Desk·48w ago
Cve-2022-29125 · Cve-2025-49725

Windows Notification Use‑After‑Free Vulnerability (CVE‑2025‑49725) Grants Attackers SYSTEM Privileges

Microsoft has patched a critical use‑after‑free vulnerability in the Windows Notification subsystem that could allow an authenticated local attacker to escalate privileges to SYSTEM. Tracked as...

SE Security Desk·48w ago
1 2 3