Microsoft Windows Server 2022 23h2 10.0.25398.1732 Azure Edition on x64

CPE Details

Microsoft Windows Server 2022 23h2 10.0.25398.1732 Azure Edition on x64
10.0.25398.1732
2025-08-15
16h50 +00:00
2025-08-15
16h50 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:microsoft:windows_server_2022_23h2:10.0.25398.1732:*:*:*:azure:*:x64:*

Informations

Vendor

microsoft

Product

windows_server_2022_23h2

Version

10.0.25398.1732

Software Edition

azure

Target Hardware

x64

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-62215 2025-11-11 17h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59502 2025-10-14 15h16 +00:00 Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
7.5
High
CVE-2025-59295 2025-10-14 15h16 +00:00 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
8.8
High
CVE-2025-59294 2025-10-14 15h16 +00:00 Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
4.6
Medium
CVE-2025-59290 2025-10-14 15h16 +00:00 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59289 2025-10-14 15h16 +00:00 Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59287 2025-10-14 15h16 +00:00 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
9.8
Critical
CVE-2025-59282 2025-10-14 15h16 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-59280 2025-10-14 15h16 +00:00 Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
3.1
Low
CVE-2025-59278 2025-10-14 15h16 +00:00 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59277 2025-10-14 15h16 +00:00 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59275 2025-10-14 15h16 +00:00 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59261 2025-10-14 15h16 +00:00 Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59260 2025-10-14 15h16 +00:00 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59259 2025-10-14 15h16 +00:00 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
6.5
Medium
CVE-2025-59258 2025-10-14 15h16 +00:00 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
6.2
Medium
CVE-2025-59257 2025-10-14 15h16 +00:00 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
6.5
Medium
CVE-2025-59255 2025-10-14 15h16 +00:00 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59254 2025-10-14 15h16 +00:00 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59253 2025-10-14 15h16 +00:00 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
5.5
Medium
CVE-2025-59244 2025-10-14 15h16 +00:00 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
6.5
Medium
CVE-2025-59242 2025-10-14 15h16 +00:00 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59230 2025-10-14 15h16 +00:00 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59214 2025-10-14 15h16 +00:00 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
6.5
Medium
CVE-2025-59211 2025-10-14 15h16 +00:00 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59209 2025-10-14 15h16 +00:00 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59208 2025-10-14 15h16 +00:00 Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
7.1
High
CVE-2025-59207 2025-10-14 15h16 +00:00 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59205 2025-10-14 15h16 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59204 2025-10-14 15h16 +00:00 Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59203 2025-10-14 15h16 +00:00 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59202 2025-10-14 15h15 +00:00 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59201 2025-10-14 15h15 +00:00 Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59200 2025-10-14 15h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
7.7
High
CVE-2025-59199 2025-10-14 15h15 +00:00 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59198 2025-10-14 15h15 +00:00 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
5
Medium
CVE-2025-59197 2025-10-14 15h15 +00:00 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59196 2025-10-14 15h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59195 2025-10-14 15h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
7
High
CVE-2025-59194 2025-10-14 15h15 +00:00 Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59193 2025-10-14 15h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59192 2025-10-14 15h15 +00:00 Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59191 2025-10-14 15h15 +00:00 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59190 2025-10-14 15h15 +00:00 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
5.5
Medium
CVE-2025-59188 2025-10-14 15h15 +00:00 Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59187 2025-10-14 15h15 +00:00 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-59186 2025-10-14 15h15 +00:00 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-59185 2025-10-14 15h15 +00:00 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
6.5
Medium
CVE-2025-59184 2025-10-14 15h15 +00:00 Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-58739 2025-10-14 15h15 +00:00 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
6.5
Medium
CVE-2025-58738 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58737 2025-10-14 15h15 +00:00 Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58736 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58735 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58734 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58733 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58732 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58731 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58730 2025-10-14 15h15 +00:00 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7
High
CVE-2025-58729 2025-10-14 15h15 +00:00 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
6.5
Medium
CVE-2025-58728 2025-10-14 15h15 +00:00 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-58727 2025-10-14 15h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-58726 2025-10-14 15h15 +00:00 Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
7.5
High
CVE-2025-58725 2025-10-14 15h15 +00:00 Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-58722 2025-10-14 15h15 +00:00 Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-58720 2025-10-14 15h15 +00:00 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
7.8
High
CVE-2025-58719 2025-10-14 15h15 +00:00 Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
4.7
Medium
CVE-2025-58718 2025-10-14 15h15 +00:00 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
8.8
High
CVE-2025-58717 2025-10-14 15h15 +00:00 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
6.5
Medium
CVE-2025-58716 2025-10-14 15h15 +00:00 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
8.8
High
CVE-2025-58715 2025-10-14 15h15 +00:00 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
8.8
High
CVE-2025-58714 2025-10-14 15h15 +00:00 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-55701 2025-10-14 15h15 +00:00 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-55700 2025-10-14 15h15 +00:00 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
6.5
Medium
CVE-2025-55699 2025-10-14 15h15 +00:00 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
5.5
Medium
CVE-2025-55697 2025-10-14 15h15 +00:00 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-55696 2025-10-14 15h15 +00:00 Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-55692 2025-10-14 15h15 +00:00 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-55689 2025-10-14 15h15 +00:00 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-55687 2025-10-14 15h15 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
7.4
High
CVE-2025-55686 2025-10-14 15h15 +00:00 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-55685 2025-10-14 15h15 +00:00 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-55680 2025-10-14 15h15 +00:00 Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
High
CVE-2025-55678 2025-10-14 15h15 +00:00 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
7
High
CVE-2025-59220 2025-09-18 21h28 +00:00 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
7
High