Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
4933
Current result set after filter and search.
Exploited Flagged
4189
Rows with a non-empty exploitation signal.
Distinct CWE
162
Unique weakness classes in this view.
Modules
1528
Unique inferred driver or component labels.
Reset
Release Month
November 2025
33 CVE | last update 1 day(s) ago
Release 2025-11-11 Patch Tuesday Count 29
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59515
Windows Broadcast DVR User Service
Exploitation Less Likely
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Jongseong Kim (nevul37), SEC-agent team with ENKI WhiteHat
Hwiwon Lee (hwiwonl), SEC-agent team
CVE-2025-62213
Windows Ancillary Function Driver for WinSock
Exploitation More Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-60707
Multimedia Class Scheduler Service (MMCSS) Driver
Exploitation Less Likely
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
hazard
CVE-2025-60716
DirectX Graphics Kernel
Exploitation Less Likely
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
cyanbamboo and b2ahex
CVE-2025-59505
Windows Smart Card Reader
Exploitation Less Likely
Windows Smart Card Reader Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-62219
Microsoft Wireless Provisioning System
Exploitation Unlikely
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-60753
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to
No latest release note
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-11-11 - -
CVE-2025-59507
Windows Speech Runtime
Exploitation Unlikely
Windows Speech Runtime Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-59508
Windows Speech Recognition
Exploitation Unlikely
Windows Speech Recognition Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-62215
Windows Kernel
Exploitation Detected
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-11-11 Yes
Reported By
Microsoft Threat Intelligence Center (MSTIC) & Microsoft Security Response Center (MSRC)
CVE-2025-62217
Windows Ancillary Function Driver for WinSock
Exploitation More Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-62218
Microsoft Wireless Provisioning System
Exploitation Less Likely
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No -
CVE-2025-60723
DirectX Graphics Kernel
Exploitation Less Likely
DirectX Graphics Kernel Denial of Service Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
cyanbamboo and b2ahex
CVE-2025-59506
DirectX Graphics Kernel
Exploitation Unlikely
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
b2ahex
cyanbamboo
CVE-2025-60705
Windows Client-Side Caching
Exploitation More Likely
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-59512
Customer Experience Improvement Program (CEIP)
Exploitation More Likely
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-47179
Configuration Manager
Exploitation Less Likely
Configuration Manager Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-60721
Windows Administrator Protection
Exploitation Less Likely
Windows Administrator Protection Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:T/RC:C
2025-11-11 No
Reported By
James Forshaw with Google Project Zero
CVE-2025-59514
Microsoft Streaming Service Proxy
Exploitation Unlikely
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
CVE-2025-59509
Windows Speech Recognition
Exploitation Unlikely
Windows Speech Recognition Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-60720
Windows Transport Driver Interface (TDI) Translation Driver
Exploitation Unlikely
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
haowei yan(jingdong dawnslab)
CVE-2025-60706
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-11-11 No
Reported By
pwnky
CVE-2025-60709
Windows Common Log File System Driver
Exploitation Less Likely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
CVE-2025-59513
Windows Bluetooth RFCOM Protocol Driver
Exploitation Less Likely
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-11-11 No
CVE-2025-62220
Windows Subsystem for Linux GUI
Exploitation Unlikely
Windows Subsystem for Linux GUI Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
CVE-2025-62452
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Anonymous
CVE-2025-60715
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Sruthy TV
Manish Kumawat
Anonymous
CVE-2025-60714
Windows OLE
Exploitation Less Likely
Windows OLE Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
CVE-2025-60724
GDI+
Exploitation Less Likely
GDI+ Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-11-11 No
Reported By
Release 2025-11-05 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-61099
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-05 - -
Release 2025-11-02 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-61104
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-02 - -
CVE-2025-61101
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-02 - -
CVE-2025-61100
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-11-02 - -
Release Month
October 2025
17 CVE | last update 1 day(s) ago
Release 2025-10-31 Other / OOB Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-61105
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61107
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61106
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61103
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
CVE-2025-61102
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a
No latest release note
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-10-31 - -
Release 2025-10-24 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-62813
LZ4 through 1.10.0 allows attackers to cause a
No latest release note
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
2025-10-24 - -
Release 2025-10-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-62168
Squid vulnerable to
No latest release note
Squid vulnerable to information disclosure via authentication credential leakage in error handling
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
2025-10-19 - -
Release 2025-10-14 Patch Tuesday Count 10
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-59204
Windows Management Services
Exploitation Unlikely
Windows Management Services Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Taewoo (Tae_ω02)
CVE-2025-59194
Windows Kernel
Exploitation More Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Muhammad Faathin Abdurrahman
CVE-2025-59213
Configuration Manager
Exploitation Less Likely
Configuration Manager Elevation of Privilege Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-55320
Configuration Manager
Exploitation Less Likely
Configuration Manager Elevation of Privilege Vulnerability
CVSS vector: AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-59207
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-55677
Windows Device Association Broker Service
Exploitation Unlikely
Windows Device Association Broker Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Hwiwon Lee (hwiwonl), SEC-agent team
Jongseong Kim (nevul37), SEC-agent team with ENKI WhiteHat
CVE-2025-24990
Windows Agere Modem Driver
Exploitation Detected
Windows Agere Modem Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-10-14 Yes
Reported By
CVE-2025-59281
Xbox Gaming Services
Exploitation Less Likely
Xbox Gaming Services Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Dominic Littlewood
CVE-2025-59241
Windows Health and Optimized Experiences
Exploitation Less Likely
Windows Health and Optimized Experiences Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-10-14 No
Reported By
CVE-2025-59203
Windows State Repository API Server File
Exploitation Less Likely
Windows State Repository API Server File Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-10-14 No
Reported By
Prev Page 10 / 99 | rows 451-500 of 4933 Next