Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-22T10:50:34Z
Freshness
52 minute(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
4943
Current result set after filter and search.
Exploited Flagged
4193
Rows with a non-empty exploitation signal.
Distinct CWE
162
Unique weakness classes in this view.
Modules
1535
Unique inferred driver or component labels.
Reset
Release Month
April 2025
13 CVE | last update 52 minute(s) ago
Release 2025-04-08 Patch Tuesday Count 13
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-29808
Windows Cryptographic Services
Exploitation Less Likely
Windows Cryptographic Services Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-04-08 No -
CVE-2025-27477
Windows Telephony Service
Exploitation Less Likely
Windows Telephony Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
CVE-2025-21222
Windows Telephony Service
Exploitation Less Likely
Windows Telephony Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Floriel (EPIN)
CVE-2025-21221
Windows Telephony Service
Exploitation Less Likely
Windows Telephony Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Floriel (EPIN)
CVE-2025-21205
Windows Telephony Service
Exploitation Less Likely
Windows Telephony Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Floriel (EPIN)
CVE-2025-26668
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
CVE-2025-26674
Windows Media
Exploitation Less Likely
Windows Media Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
CVE-2025-26666
Windows Media
Exploitation Less Likely
Windows Media Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
CVE-2025-27478
Windows Local Security Authority (LSA)
Exploitation Less Likely
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
CVE-2025-27490
Windows Bluetooth Service
Exploitation Less Likely
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Erik Peterson with Microsoft Corporation
Robert Zhao and Erik Peterson with Microsoft Corporation
CVE-2025-27487
Remote Desktop Client
Exploitation Less Likely
Remote Desktop Client Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Josh Watson with Microsoft
Nicholas Vadasz with Microsoft
Philemon Orphee Favrod with Microsoft
CVE-2025-27481
Windows Telephony Service
Exploitation Less Likely
Windows Telephony Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Reported By
Anonymous
CVE-2025-26688
Microsoft Virtual Hard Disk
Exploitation Less Likely
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-04-08 No
Release Month
March 2025
37 CVE | last update 52 minute(s) ago
Release 2025-03-20 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-29814
Microsoft Partner Center
N/A
Microsoft Partner Center Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H/E:P/RL:O/RC:C
2025-03-20 No
Reported By
Anonymous
Release 2025-03-19 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential
No latest release note
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
2025-03-19 - -
CVE-2025-25724
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a
No latest release note
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-byte buffer may not be sufficient for a custom locale.
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
2025-03-19 - -
CVE-2025-27220
In the CGI gem before 0.4.2 for Ruby, a Regular Expression
No latest release note
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L
2025-03-19 - -
Release 2025-03-14 Other / OOB Count 12
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2018-7263
The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a
No latest release note
The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2025-03-14 - -
CVE-2017-11551
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a
No latest release note
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2015-2158
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a
No latest release note
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
2025-03-14 - -
CVE-2015-8126
Multiple buffer overflows in libpng allow remote attackers to cause a
No latest release note
Multiple buffer overflows in libpng allow remote attackers to cause a denial of service
No CVSS vector published
2025-03-14 - -
CVE-2015-8472
Buffer overflow in libpng allows remote attackers to cause a
No latest release note
Buffer overflow in libpng allows remote attackers to cause a denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
2025-03-14 - -
CVE-2022-43358
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a
No latest release note
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2022-43357
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea
No latest release note
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2024-49769
Waitress has a
No latest release note
Waitress has a denial of service leading to high CPU usage/resource exhaustion
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2025-21690
scsi: storvsc: Ratelimit warning logs to prevent VM
No latest release note
scsi: storvsc: Ratelimit warning logs to prevent VM denial of service
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2017-11550
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a
No latest release note
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2024-25112
QuickTimeVideo::multipleEntriesDecoder in Exiv2
No latest release note
Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-03-14 - -
CVE-2025-0426
A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node
No latest release note
A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-03-14 - -
Release 2025-03-11 Patch Tuesday Count 21
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-24084
Windows Subsystem for Linux (WSL2) Kernel
Exploitation Less Likely
Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Benoît Sevens and Vlad Stolyarov of Google Threat Analysis Group
CVE-2025-24059
Windows Common Log File System Driver
Exploitation Less Likely
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Anonymous
CVE-2025-25008
Windows Server
Exploitation Less Likely
Windows Server Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Lockheed Martin Red Team
CVE-2025-24045
Windows Remote Desktop Services
Exploitation More Likely
Windows Remote Desktop Services Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
ʌ!ɔ⊥ojv with Kunlun Lab
Ashana Sharan with Microsoft India
CVE-2025-24035
Windows Remote Desktop Services
Exploitation More Likely
Windows Remote Desktop Services Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
ʌ!ɔ⊥ojv with Kunlun Lab
Anonymous
CVE-2025-24984
Windows NTFS
Exploitation Detected
Windows NTFS Information Disclosure Vulnerability
CVSS vector: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C
2025-03-11 Yes
Reported By
Anonymous
CVE-2025-24997
DirectX Graphics Kernel File
Exploitation Less Likely
DirectX Graphics Kernel File Denial of Service Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Benoît Sevens and Vlad Stolyarov of Google Threat Analysis Group
CVE-2025-24983
Windows Win32 Kernel Subsystem
Exploitation Detected
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-03-11 Yes
Reported By
Filip Jurčacko with ESET
CVE-2025-24044
Windows Win32 Kernel Subsystem
Exploitation More Likely
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
George Hughey with MSRC Vulnerabilities & Mitigations
Benjamin Rodes from Microsoft
CVE-2025-24064
Windows Domain Name Service
Exploitation Less Likely
Windows Domain Name Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Jay Ladhad with Microsoft
CVE-2025-24072
Microsoft Local Security Authority (LSA) Server
Exploitation Less Likely
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Florian Schweins
CVE-2025-24046
Kernel Streaming Service Driver
Exploitation Less Likely
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
CVE-2025-24043
WinDbg
Exploitation Less Likely
WinDbg Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No -
CVE-2025-24994
Microsoft Windows Cross Device Service
Exploitation Less Likely
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
John Ostrowski with Compass Security
CVE-2025-24076
Microsoft Windows Cross Device Service
Exploitation Less Likely
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
John Ostrowski with Compass Security
CVE-2025-26645
Remote Desktop Client
Exploitation Less Likely
Remote Desktop Client Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No -
CVE-2025-24985
Windows Fast FAT File System Driver
Exploitation Detected
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
2025-03-11 Yes
Reported By
Anonymous
CVE-2025-24992
Windows NTFS
Exploitation More Likely
Windows NTFS Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-03-11 No
Reported By
George Hughey with MSRC Vulnerabilities & Mitigations
CVE-2025-24988
Windows USB Video Class System Driver
Exploitation Less Likely
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Adel and Benjamin Rodes.
CVE-2025-24987
Windows USB Video Class System Driver
Exploitation Less Likely
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Adel and Benjamin Rodes
CVE-2025-24055
Windows USB Video Class System Driver
Exploitation Less Likely
Windows USB Video Class System Driver Information Disclosure Vulnerability
CVSS vector: AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-03-11 No
Reported By
Adel from MSRC V&M
Prev Page 23 / 99 | rows 1101-1150 of 4943 Next