Live
Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers·MSFT +0.1%Siemens Patches Critical Simcenter Femap Bugs Allowing Code Execution from Malicious STP and BMP Files·NVDA +3.0%Siemens RTLS Backup Script Vulnerability Allows Full SYSTEM Takeover·GOOGL +1.2%Siemens Flags CVSS 8.5 DLL Hijacking in Web Installer, Urges Immediate Mitigation for ICS Products·AMZN +2.9%CVE-2025-47957: Decoding Microsoft’s Critical Word Use-After-Free Vulnerability·MSFT +0.1%Actively Exploited Windows AFD.sys Flaw Earns CISA KEV Status Amid Patching Confusion·NVDA +3.0%CVE-2025-25005: The Windows Vulnerability Shrouded in Uncertainty and What Admins Must Do Now·GOOGL +1.2%Microsoft Discloses Critical PowerPoint Use-After-Free Flaw, CVE-2025-53761, Enabling Local Code Execution·AMZN +2.9%Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers·MSFT +0.1%Siemens Patches Critical Simcenter Femap Bugs Allowing Code Execution from Malicious STP and BMP Files·NVDA +3.0%Siemens RTLS Backup Script Vulnerability Allows Full SYSTEM Takeover·GOOGL +1.2%Siemens Flags CVSS 8.5 DLL Hijacking in Web Installer, Urges Immediate Mitigation for ICS Products·AMZN +2.9%CVE-2025-47957: Decoding Microsoft’s Critical Word Use-After-Free Vulnerability·MSFT +0.1%Actively Exploited Windows AFD.sys Flaw Earns CISA KEV Status Amid Patching Confusion·NVDA +3.0%CVE-2025-25005: The Windows Vulnerability Shrouded in Uncertainty and What Admins Must Do Now·GOOGL +1.2%Microsoft Discloses Critical PowerPoint Use-After-Free Flaw, CVE-2025-53761, Enabling Local Code Execution·AMZN +2.9%

Nvd

The latest Nvd coverage — news, analysis, and updates from the WindowsNews.AI desk.

9 stories in view AI assisted desk updated 11:21 AM
Latest Most Read Breaking
Sort
Browser Security · Chrome

Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers

A critical logic flaw in Chromium's File Picker—one of the browser's most sensitive UI components—can be weaponized to leak data across origins, forcing Google and Microsoft to ship urgent...

Advertisement
Cve-2025-47957 · Cybersecurity

CVE-2025-47957: Decoding Microsoft’s Critical Word Use-After-Free Vulnerability

Microsoft’s security team recently pushed out a fix for a critical vulnerability in Microsoft Word that, if left unpatched, could give attackers a direct path to executing malicious code on a...

SE Security Desk·48w ago
Afd.sys · Cisa

Actively Exploited Windows AFD.sys Flaw Earns CISA KEV Status Amid Patching Confusion

Microsoft’s February 2025 Patch Tuesday delivered a fix for CVE-2025-21418, a heap-based buffer overflow in the Windows Ancillary Function Driver (afd.sys), but sysadmins are grappling with a...

SE Security Desk·48w ago
Adminguides · Cisa

CVE-2025-25005: The Windows Vulnerability Shrouded in Uncertainty and What Admins Must Do Now

The discovery of a new Windows vulnerability always triggers a scramble for details, but CVE-2025-25005 has presented an unusual challenge: the Microsoft Security Response Center (MSRC) advisory...

SE Security Desk·48w ago
Asr · Cve-2025-53761

Microsoft Discloses Critical PowerPoint Use-After-Free Flaw, CVE-2025-53761, Enabling Local Code Execution

Microsoft has issued a security advisory for a new use-after-free vulnerability in PowerPoint, tracked as CVE-2025-53761, that allows an unauthorized attacker to execute code locally. The flaw, which...

SE Security Desk·48w ago
Cve-2025-53770 · Cybersecurity

SharePoint 'ToolShell' Zero-Day Exploited: Critical RCE Patched Amid Active Attacks

Microsoft has released an emergency security update to patch a critical remote code execution (RCE) vulnerability in SharePoint Server that has been actively exploited in the wild. Tracked as...

SE Security Desk·48w ago