Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
76
Current result set after filter and search.
Exploited Flagged
76
Rows with a non-empty exploitation signal.
Distinct CWE
3
Unique weakness classes in this view.
Modules
59
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-284: Improper Access Control Clear filters
Release Month
May 2026
1 CVE | last update 1 day(s) ago
Release 2026-05-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-33834
Windows Event Logging Service
Exploitation Less Likely
Windows Event Logging Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-05-12 No
Reported By
George Hughey with MSRC Vulnerabilities & Mitigations
Release Month
April 2026
4 CVE | last update 1 day(s) ago
Release 2026-04-23 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-24303
Microsoft Partner Center
N/A
Microsoft Partner Center Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
2026-04-23 No
Reported By
Shyam Datti with Microsoft Corporation
Release 2026-04-14 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-32214
Universal Plug and Play (upnp.dll)
Exploitation Less Likely
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Anonymous
CVE-2026-26183
Remote Access Management service/API (RPC server)
Exploitation Less Likely
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
George Hughey with MSRC Vulnerabilities & Mitigations
CVE-2026-27914
Microsoft Management Console
Exploitation More Likely
Microsoft Management Console Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-04-14 No
Reported By
Release Month
March 2026
2 CVE | last update 1 day(s) ago
Release 2026-03-10 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-24290
Windows Projected File System
Exploitation Less Likely
Windows Projected File System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
ChenJian with Sea Security Orca Team
CVE-2026-25176
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-03-10 No
Reported By
Release Month
February 2026
2 CVE | last update 1 day(s) ago
Release 2026-02-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-21535
Microsoft Teams
Exploitation Unlikely
Microsoft Teams Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
2026-02-19 No
Reported By
Release 2026-02-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-21238
Windows Ancillary Function Driver for WinSock
Exploitation More Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-02-10 No
Reported By
Release Month
January 2026
5 CVE | last update 1 day(s) ago
Release 2026-01-13 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2026-20843
Windows Routing and Remote Access Service (RRAS)
Exploitation More Likely
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
CVE-2026-20825
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Andrey Markovytch
CVE-2026-20929
Windows HTTP.sys
Exploitation Unlikely
Windows HTTP.sys Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Andrea Pierini with Semperis
Ben Zamir with Cymulate
Howard McGreehan with MSRC V&M
CVE-2026-0386
Windows Deployment Services
Exploitation Unlikely
Windows Deployment Services Remote Code Execution Vulnerability
CVSS vector: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Microsoft Offensive Research and Security Engineering (MORSE) with Microsoft
CVE-2026-20839
Windows Client-Side Caching (CSC) Service
Exploitation Unlikely
Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2026-01-13 No
Reported By
Microsoft Offensive Research & Security Engineering
Release Month
December 2025
5 CVE | last update 1 day(s) ago
Release 2025-12-09 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-64673
Windows Storage VSP Driver
Exploitation Less Likely
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
CVE-2025-59517
Windows Storage VSP Driver
Exploitation More Likely
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
CVE-2025-62474
Windows Remote Access Connection Manager
Exploitation Less Likely
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Reported By
Microsoft Threat Intelligence Center (MSTIC) & Microsoft Security Response Center (MSRC)
CVE-2025-62570
Windows Camera Frame Server Monitor
Exploitation Less Likely
Windows Camera Frame Server Monitor Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
2025-12-09 No
CVE-2025-64669
Windows Admin Center
Exploitation Less Likely
Windows Admin Center Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-12-09 No
Release Month
November 2025
3 CVE | last update 1 day(s) ago
Release 2025-11-11 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-60705
Windows Client-Side Caching
Exploitation More Likely
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-59512
Customer Experience Improvement Program (CEIP)
Exploitation More Likely
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-47179
Configuration Manager
Exploitation Less Likely
Configuration Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Release Month
October 2025
8 CVE | last update 1 day(s) ago
Release 2025-10-14 Patch Tuesday Count 8
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59253
Windows Search Service
Exploitation Less Likely
Windows Search Service Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Remco van der Meer with Warpnet
CVE-2025-58726
Windows SMB Server
Exploitation Less Likely
Windows SMB Server Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-59230
Windows Remote Access Connection Manager
Exploitation Detected
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-10-14 Yes
Reported By
Microsoft Threat Intelligence Center (MSTIC) & Microsoft Security Response Center (MSRC)
CVE-2025-55694
Windows Error Reporting Service
Exploitation More Likely
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Denis Faiustov and Ruslan Sayfiev with GMO Cybersecurity by Ierae
CVE-2025-58714
Windows Ancillary Function Driver for WinSock
Exploitation Unlikely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-59199
Software Protection Platform (SPP)
Exploitation More Likely
Software Protection Platform (SPP) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Yarin Aharoni with SafeBreach
CVE-2025-25004
PowerShell
Exploitation Less Likely
PowerShell Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Casper
tsuki
CVE-2025-59201
Network Connection Status Indicator (NCSI)
Exploitation Less Likely
Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Release Month
September 2025
2 CVE | last update 1 day(s) ago
Release 2025-09-09 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-54116
Windows MultiPoint Services
Exploitation Unlikely
Windows MultiPoint Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
CVE-2025-54098
Windows Hyper-V
Exploitation More Likely
Windows Hyper-V Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Release Month
July 2025
2 CVE | last update 1 day(s) ago
Release 2025-07-08 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-47993
Microsoft PC Manager
Exploitation Less Likely
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No
Reported By
Filip Dragovic (@filip_dragovic) working with Trend Zero Day Initiative
CVE-2025-48817
Remote Desktop Client
Exploitation Less Likely
Remote Desktop Client Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-07-08 No -
Release Month
June 2025
5 CVE | last update 1 day(s) ago
Release 2025-06-10 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-32722
Windows Storage Port Driver
Exploitation Less Likely
Windows Storage Port Driver Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-06-10 No
Reported By
CVE-2025-33073
Windows SMB Client
Exploitation Less Likely
Windows SMB Client Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
2025-06-10 No
Reported By
James Forshaw of Google Project Zero
RedTeam Pentesting GmbH
Stefan Walter and Daniel Isern with SySS GmbH
Ahamada M'Bamba (h1roki)
Cameron Stish with GuidePoint Security
Wilfried Bécard with Synacktiv
Keisuke Hirata with CrowdStrike
CVE-2025-47962
Windows SDK
Exploitation More Likely
Windows SDK Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-06-10 No
Reported By
whoisthatguy
Naor Hodorov
Kolja Grassmann with Neodyme AG
Ken Kitahara with LAC Co., Ltd.
Robbie Corley
Julian Härig
CVE-2025-33056
Windows Local Security Authority (LSA)
Exploitation Less Likely
Windows Local Security Authority (LSA) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-06-10 No
Reported By
CVE-2025-32714
Windows Installer
Exploitation More Likely
Windows Installer Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-06-10 No
Reported By
Simon Zuckerbraun of Trend Zero Day Initiative
Release Month
April 2025
3 CVE | last update 1 day(s) ago
Release 2025-04-08 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-27738
Windows Resilient File System (ReFS)
Exploitation Less Likely
Windows Resilient File System (ReFS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Sébastien Huneault with Cégep de l'Outaouais
CVE-2025-21197
Windows NTFS
Exploitation Less Likely
Windows NTFS Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Sébastien Huneault with CyberQuébec
CVE-2025-29810
Active Directory Domain Services
Exploitation Less Likely
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Matthieu Buffet
Release Month
March 2025
3 CVE | last update 1 day(s) ago
Release 2025-03-11 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-24994
Microsoft Windows Cross Device Service
Exploitation Less Likely
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
John Ostrowski with Compass Security
CVE-2025-24076
Microsoft Windows Cross Device Service
Exploitation Less Likely
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
John Ostrowski with Compass Security
CVE-2025-26645
Remote Desktop Client
Exploitation Less Likely
Remote Desktop Client Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No -
Release Month
February 2025
2 CVE | last update 1 day(s) ago
Release 2025-02-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-24989
Microsoft Power Pages
Exploitation Detected
Microsoft Power Pages Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C
2025-02-19 Yes
Reported By
Raj Kumar with Microsoft
Release 2025-02-11 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-21337
Windows NTFS
Exploitation Less Likely
Windows NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
2025-02-11 No
Reported By
hazard
Release Month
January 2025
3 CVE | last update 1 day(s) ago
Release 2025-01-14 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-21202
Windows Recovery Environment Agent
Exploitation Less Likely
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
CVSS vector: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
2025-01-14 No
Reported By
Maxim Suhanov with CICADA8
CVE-2025-21301
Windows Geolocation Service
Exploitation Less Likely
Windows Geolocation Service Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-01-14 No
Reported By
André Schoorl and Bruno Pereira Vidal
Bruno Pereira Vidal
CVE-2025-21293
Active Directory Domain Services
Exploitation Less Likely
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-01-14 No
Page 1 / 2 | rows 1-50 of 76 Next