Known vulnerabilities in Windows Server 2025 10.0.26100.2605 - page 48

Vendor: Microsoft
Version: 2025 10.0.26100.2605
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 1627
Public exploits: 49
Known exploited (KEV): 38
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2025 10.0.26100.2605 Windows Server 2025 10.0.26100.2605 is affected by 1627 vulnerabilities: 7 critical, 263 high, 300 medium, 1056 low Critical High Medium Low

Vulnerabilities (1627)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117194 - Improper Access Control
CVE-2025-59201
CWE-284 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101547
#VU117193 - Use After Free
CVE-2025-50174
CWE-416 Low
No
No
2022 23H2 10.0.25398.1913, 2025 10.0.26100.6899 15.10.2025 SB2025101546
#VU117192 - Untrusted Pointer Dereference
CVE-2025-55677
CWE-822 Low
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101546
#VU117191 - Use After Free
CVE-2025-58737
CWE-416 High
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101545
#VU117190 - Heap-based Buffer Overflow
CVE-2025-58725
CWE-122 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101544
#VU117189 - Out-of-bounds read
CVE-2025-59208
CWE-125 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101543
#VU117188 - Stack-based buffer overflow
CVE-2025-24052
CWE-121 Low
Public exploit available
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101541
#VU117187 - Use After Free
CVE-2025-55335
CWE-416 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101540
#VU117186 - Out-of-bounds read
CVE-2025-55339
CWE-125 Low
No
No
2012 R2 6.3.9600.22824, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101539
#VU117184 - Information Exposure Through an Error Message
CVE-2025-55676
CWE-209 Low
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101537
#VU117181 - Use After Free
CVE-2025-59206
CWE-416 Low
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101536
#VU117180 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-55687
CWE-362 Low
No
No
2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101536
#VU117179 - Out-of-bounds read
CVE-2025-55700
CWE-125 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101535
#VU117178 - Out-of-bounds read
CVE-2025-58717
CWE-125 Medium
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101535
#VU117176 - Integer overflow
CVE-2025-58715
CWE-190 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101532
#VU117175 - Improper input validation
CVE-2025-58716
CWE-20 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101532
#VU117174 - External Control of File Name or Path
CVE-2025-59185
CWE-73 Medium
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101531
#VU117173 - External Control of File Name or Path
CVE-2025-59244
CWE-73 Medium
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101531
#VU117172 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59260
CWE-200 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101529
#VU117170 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-59205
CWE-362 Low
No
No
2008 R2 6.1.7601.27974, 2008 6.0.6003.23571, 2012 R2 6.3.9600.22824, 2012 6.2.9200.25722, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101528


Showing elements 941 - 960 out of 1627