CVE Database

Comprehensive vulnerability intelligence with advanced analytics

5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.04%
View Details
7.8

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_11_23h2
EPSS: 0.04%
View Details
5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.04%
View Details
4.3

Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.04%
View Details
6.2

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_11_23h2
EPSS: 0.04%
View Details
7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.06%
View Details
5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.04%
View Details
8.0

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.90%
View Details
7.5

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_11_23h2
EPSS: 0.06%
View Details
5.3

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.06%
View Details
7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.06%
View Details
6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.08%
View Details
7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 16, 2026
Product: microsoft windows_server_2025
EPSS: 0.04%
View Details
7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.06%
View Details
7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_server_2022_23h2
EPSS: 0.04%
View Details
7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.06%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
6.7

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_server_2022_23h2
EPSS: 0.05%
View Details
7.5

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.12%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details