Live
Excel CVE-2025-54901: Patch Now for Critical Memory Disclosure, Mac Users Wait·MSFT +2.1%Patch Windows MultiPoint Services Immediately — CVE-2025-54116 Grants Attackers SYSTEM Access·NVDA +0.2%Microsoft’s No-Restart Patch Squashes UAC Prompts for Windows 11 LTSC, Warns of 2026 Secure Boot Crisis·GOOGL +1.7%Windows camsvc Race Condition Exploited for SYSTEM Access: Urgent Patch Deployed·AMZN +1.1%Microsoft's Brokering File System Hit by Race Condition—Attackers Can Seize SYSTEM·MSFT +2.1%Windows Firewall’s Memory Misfire: How CVE-2025-54094 Opens a Door to SYSTEM Privileges·NVDA +0.2%CVE-2025-53806: Microsoft Patches RRAS Memory Disclosure Flaw in Windows VPN Servers·GOOGL +1.7%Critical Local Privilege Escalation Bug in Windows DWM Fixed: Here’s What You Need to Know·AMZN +1.1%Excel CVE-2025-54901: Patch Now for Critical Memory Disclosure, Mac Users Wait·MSFT +2.1%Patch Windows MultiPoint Services Immediately — CVE-2025-54116 Grants Attackers SYSTEM Access·NVDA +0.2%Microsoft’s No-Restart Patch Squashes UAC Prompts for Windows 11 LTSC, Warns of 2026 Secure Boot Crisis·GOOGL +1.7%Windows camsvc Race Condition Exploited for SYSTEM Access: Urgent Patch Deployed·AMZN +1.1%Microsoft's Brokering File System Hit by Race Condition—Attackers Can Seize SYSTEM·MSFT +2.1%Windows Firewall’s Memory Misfire: How CVE-2025-54094 Opens a Door to SYSTEM Privileges·NVDA +0.2%CVE-2025-53806: Microsoft Patches RRAS Memory Disclosure Flaw in Windows VPN Servers·GOOGL +1.7%Critical Local Privilege Escalation Bug in Windows DWM Fixed: Here’s What You Need to Know·AMZN +1.1%

Vulnerability

The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 12:14 AM
Latest Most Read Breaking
Sort
Aslr · Buffer Over-read

Excel CVE-2025-54901: Patch Now for Critical Memory Disclosure, Mac Users Wait

Microsoft has released emergency security updates to patch a significant information-disclosure vulnerability in Microsoft Excel, tracked as CVE-2025-54901, that can expose sensitive process memory...

Advertisement
Bfs · Brokering File System

Microsoft's Brokering File System Hit by Race Condition—Attackers Can Seize SYSTEM

Microsoft has confirmed a local elevation-of-privilege vulnerability in its Brokering File System that hands a low-privileged local user a pathway to full SYSTEM control. Tracked as CVE-2025-54105,...

SE Security Desk·45w ago
Application Control · Cve-2025-54094

Windows Firewall’s Memory Misfire: How CVE-2025-54094 Opens a Door to SYSTEM Privileges

A newly disclosed privilege escalation vulnerability in the Windows Defender Firewall Service allows attackers with a foothold on a system to seize complete control, elevating standard user...

SE Security Desk·45w ago
Cve-2025-53806 · Information Disclosure

CVE-2025-53806: Microsoft Patches RRAS Memory Disclosure Flaw in Windows VPN Servers

Microsoft has disclosed CVE-2025-53806, a new information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows attackers to read sensitive memory contents from...

SE Security Desk·45w ago
Cve-2025-53801 · Dwm Core Library

Critical Local Privilege Escalation Bug in Windows DWM Fixed: Here’s What You Need to Know

Microsoft has patched a serious local privilege escalation vulnerability in the Windows Desktop Window Manager (DWM) Core Library, tracked as CVE-2025-53801, that could allow an attacker with a basic...

SE Security Desk·45w ago
Cve-2025-53803 · Cybersecurity

Microsoft Patches Windows Kernel Memory Leak (CVE-2025-53803) That Facilitates Privilege Escalation

Microsoft has released a security update to close a Windows kernel memory disclosure vulnerability that hands attackers a powerful reconnaissance tool for crafting more reliable exploits. Tracked as...

SE Security Desk·45w ago
Azcmagent · Azure Arc

CVE-2025-49692: Azure Connected Machine Agent Vulnerability Demands Immediate Patching

Microsoft has released a security update to address a critical elevation-of-privilege vulnerability (CVE-2025-49692) in the Azure Connected Machine agent, the software component that enables Azure...

SE Security Desk·45w ago
Credential Theft · Cu Update

SQL Server Vulnerability CVE-2025-47997: Patch Now to Block Memory Disclosure Attacks

Microsoft has released patches for a critical information-disclosure vulnerability in SQL Server that could allow an authenticated attacker to read sensitive memory contents over the network. Tracked...

SE Security Desk·45w ago
Cve-2025-55317 · Cybersecurity

Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks

Microsoft has disclosed a fresh local elevation-of-privilege vulnerability in its Microsoft AutoUpdate (MAU) agent that allows an attacker with an existing foothold on a macOS machine to escalate to...

SE Security Desk·45w ago