Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
269
Current result set after filter and search.
Exploited Flagged
234
Rows with a non-empty exploitation signal.
Distinct CWE
13
Unique weakness classes in this view.
Modules
128
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-125: Out-of-bounds Read Clear filters
Release Month
May 2026
3 CVE | last update 1 day(s) ago
Release 2026-05-12 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-35419
Windows DWM Core Library
Exploitation Less Likely
Windows DWM Core Library Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-05-12 No
CVE-2026-35423
Windows 11 Telnet Client
Exploitation Unlikely
Windows 11 Telnet Client Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Microsoft
CVE-2026-40380
Windows Volume Manager Extension Driver
Exploitation Less Likely
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
CVSS vector: AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
Calif.io in collaboration with Claude and Anthropic Research
Release Month
April 2026
7 CVE | last update 1 day(s) ago
Release 2026-04-29 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-34003
Xorg: xwayland: x.org x server: information exposure and
No latest release note
Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-04-29 - -
Release 2026-04-14 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32076
Windows Storage Spaces Controller
Exploitation Less Likely
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Yoon Jung Hyun(Yuil Muil (@YuilMuil) / X)
CVE-2026-27931
Windows GDI
Exploitation Less Likely
Windows GDI Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
xina1i@psbc
CVE-2026-27930
Windows GDI
Exploitation Less Likely
Windows GDI Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
xina1i@psbc
CVE-2026-26153
Windows Encrypted File System (EFS)
Exploitation Less Likely
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Hangyu Hua(@HBh25Y) with Shuffle Team and Hunan University
CVE-2026-33096
HTTP.sys
Exploitation Less Likely
HTTP.sys Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
WARP & MORSE teams at Microsoft
Milad Nasr (Anthropic) and Calif.io with Claude
CVE-2026-26156
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
cyanbamboo and b2ahex
Release Month
March 2026
8 CVE | last update 1 day(s) ago
Release 2026-03-25 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-4424
Libarchive: libarchive
No latest release note
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2026-03-25 - -
Release 2026-03-10 Patch Tuesday Count 7
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-23672
Windows Universal Disk Format File System Driver (UDFS)
Exploitation Unlikely
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Microsoft
CVE-2026-23673
Windows Resilient File System (ReFS)
Exploitation Unlikely
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Microsoft
CVE-2026-25175
Windows NTFS
Exploitation Less Likely
Windows NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Microsoft
CVE-2026-25180
Windows Graphics Component
Exploitation Less Likely
Windows Graphics Component Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-03-10 No
Reported By
CVE-2026-25174
Windows Extensible File Allocation Table
Exploitation Unlikely
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Microsoft
CVE-2026-24282
Push message Routing Service
Exploitation Less Likely
Push message Routing Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Anonymous
CVE-2026-25181
GDI+
Exploitation Less Likely
GDI+ Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Anonymous working with TrendAI Zero Day Initiative
Release Month
February 2026
2 CVE | last update 1 day(s) ago
Release 2026-02-21 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-2443
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap
No latest release note
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
2026-02-21 - -
Release 2026-02-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-21247
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-02-10 No
Reported By
cyanbamboo and b2ahex
Release Month
January 2026
5 CVE | last update 1 day(s) ago
Release 2026-01-13 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-20828
Windows rndismp6.sys
Exploitation Less Likely
Windows rndismp6.sys Information Disclosure Vulnerability
CVSS vector: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No
Reported By
B1aN
CVE-2026-20936
Windows NDIS
Exploitation Unlikely
Windows NDIS Information Disclosure Vulnerability
CVSS vector: AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No -
CVE-2026-20829
TPM Trustlet
Exploitation Less Likely
TPM Trustlet Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Microsoft Offensive Research & Security Engineering
CVE-2026-20851
Capability Access Management Service (camsvc)
Exploitation Less Likely
Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No
Reported By
CVE-2026-20835
Capability Access Management Service (camsvc)
Exploitation Less Likely
Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No
Release Month
December 2025
3 CVE | last update 1 day(s) ago
Release 2025-12-09 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-55233
Windows Projected File System
Exploitation Unlikely
Windows Projected File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
ChenJian with Sea Security Orca Team
CVE-2025-62457
Windows Cloud Files Mini Filter Driver
Exploitation Unlikely
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
haowei yan(jingdong dawnslab)
CVE-2025-62572
Application Information Service
Exploitation Less Likely
Application Information Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
Pwnforr777
Release Month
November 2025
3 CVE | last update 1 day(s) ago
Release 2025-11-11 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-60706
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-11-11 No
Reported By
pwnky
CVE-2025-60709
Windows Common Log File System Driver
Exploitation Less Likely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
CVE-2025-59513
Windows Bluetooth RFCOM Protocol Driver
Exploitation Less Likely
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-11-11 No
Release Month
October 2025
11 CVE | last update 1 day(s) ago
Release 2025-10-14 Patch Tuesday Count 8
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59275
Windows Authentication
Exploitation Less Likely
Windows Authentication Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-55695
Windows WLAN AutoConfig Service
Exploitation Unlikely
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-10-14 No
CVE-2025-58717
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Anonymous
CVE-2025-55700
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Anonymous
CVE-2025-55339
Windows Network Driver Interface Specification (NDIS) Driver
Exploitation Less Likely
Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-59208
Windows MapUrlToZone
Exploitation Less Likely
Windows MapUrlToZone Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
2025-10-14 No
Reported By
George Hughey with MSRC Vulnerabilities & Mitigations
CVE-2025-50152
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Anonymous
CVE-2025-55681
Desktop Window Manager
Exploitation More Likely
Desktop Window Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Release 2025-10-01 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-12613
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an
No latest release note
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may represent an information disclosure or denial of service vulnerability to applications which call these APR functions with unvalidated external input.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
2025-10-01 - -
CVE-2017-5834
The parse_dict_node function in bplist.c in libplist allows attackers to cause a
No latest release note
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-10-01 - -
CVE-2017-6829
The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a
No latest release note
The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-10-01 - -
Release Month
September 2025
8 CVE | last update 1 day(s) ago
Release 2025-09-09 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-53806
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-55225
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54097
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54096
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54095
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-53805
HTTP.sys
Exploitation Unlikely
HTTP.sys Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Rutuja Shirali with Microsoft
Yesayi Hovnanyan with Microsoft
Matthew Cox with Microsoft
Release 2025-09-04 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-7718
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a
No latest release note
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2025-09-04 - -
Release 2025-09-03 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2016-8681
The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a
No latest release note
The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
Page 1 / 6 | rows 1-50 of 269 Next