Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 82/380
7.8
CVE-2025-54912

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

7.3
CVE-2025-54911

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

8.4
CVE-2025-54910

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54908

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54907

Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54906

Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-54905

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-54904

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54903

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54902

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

5.5
CVE-2025-54901

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-54900

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54899

Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54898

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-54897

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

7.8
CVE-2025-54896

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54895

Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privilege

7.8
CVE-2025-54894

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

7.3
CVE-2025-54116

Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-54115

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an

7.0
CVE-2025-54114

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices

8.8
CVE-2025-54113

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

7.0
CVE-2025-54112

Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-54111

Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-54110

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

6.7
CVE-2025-54109

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

7.0
CVE-2025-54108

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

4.3
CVE-2025-54107

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea

8.8
CVE-2025-54106

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to ex

7.0
CVE-2025-54105

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File

6.7
CVE-2025-54104

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

7.4
CVE-2025-54103

Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2025-54102

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

4.8
CVE-2025-54101

Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

7.0
CVE-2025-54099

Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pr

7.8
CVE-2025-54098

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

6.5
CVE-2025-54097

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-54096

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-54095

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.7
CVE-2025-54094

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

7.0
CVE-2025-54093

Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges

7.8
CVE-2025-54092

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an

7.8
CVE-2025-54091

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

6.7
CVE-2025-53810

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

6.5
CVE-2025-53809

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to

6.7
CVE-2025-53808

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

7.0
CVE-2025-53807

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

6.5
CVE-2025-53806

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa

7.5
CVE-2025-53805

Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a netwo

5.5
CVE-2025-53804

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started