PatchSiren

Microsoft CVE debriefs · Page 61

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2025-11-12

CVE-2025-62215

CVE-2025-62215 is a Microsoft Windows race condition vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-11-12. Because it is in KEV, organizations should treat it as a priority defensive item and follow Microsoft’s guidance and any applicable CISA remediation requirements. The supplied corpus does not include a CVSS score or version-specific impact details.

HIGH Microsoft CVE published 2025-11-11

CVE-2025-62199

CVE-2025-62199 is a Microsoft Office use-after-free vulnerability (CWE-416) publicly disclosed on 2025-11-11 and later modified on 2025-11-19. The official NVD record rates it HIGH (CVSS 7.8) with a local attack vector, no privileges required, but user interaction required; successful exploitation can impact confidentiality, integrity, and availability at a high level. The NVD CPE list indicates exposure [truncated]

CRITICAL Microsoft CVE published 2025-11-11

CVE-2025-60724

CVE-2025-60724 is a critical remote code execution issue in Microsoft Graphics Component. The supplied Microsoft/NVD record describes a heap-based buffer overflow (CWE-122) that can let an unauthorized attacker execute code over the network. NVD rates the flaw CVSS 9.8 with AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which is the strongest signal here for urgent patching. The NVD record also links to the Microso [truncated]

Known exploited Microsoft CVE published 2025-10-24

CVE-2025-59287

CVE-2025-59287 is a Microsoft Windows Server Update Service (WSUS) deserialization of untrusted data vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-24, which signals active exploitation and makes remediation an urgent priority for Windows environments that run WSUS.

Known exploited Microsoft CVE published 2025-10-20

CVE-2025-33073

CVE-2025-33073 is a Microsoft Windows SMB Client improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-10-20. That KEV listing makes this a high-priority issue for defenders because CISA has set a remediation deadline of 2025-11-10 and directs organizations to apply vendor mitigations promptly. The public source corpus here does not include Microsoft [truncated]

HIGH Microsoft CVE published 2025-10-14

CVE-2025-59234

CVE-2025-59234 is a Microsoft Office use-after-free vulnerability that can allow an unauthorized attacker to execute code locally. Microsoft rates the issue high severity, and NVD lists a CVSS 3.1 score of 7.8 with a vector indicating local access, required user interaction, and high impact to confidentiality, integrity, and availability.

HIGH Microsoft CVE published 2025-10-14

CVE-2025-59227

CVE-2025-59227 is a high-severity Microsoft Office use-after-free vulnerability that can lead to local code execution. NVD maps the issue to multiple Office product lines, including Microsoft 365 Apps, Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Office for Android, with Microsoft’s advisory as the referenced vendor source. The CVSS vector indicates local exploitation, low attack comp [truncated]

Known exploited Microsoft CVE published 2025-10-14

CVE-2025-59230

CVE-2025-59230 is a Microsoft Windows improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-10-14. Because it appears in KEV, defenders should treat it as a high-priority issue and move quickly on vendor-directed mitigation or patching. The supplied corpus does not include a CVSS score or deeper technical details, but it does establish that exploitati [truncated]

Known exploited Microsoft CVE published 2025-10-14

CVE-2025-24990

CVE-2025-24990 is a Microsoft Windows untrusted pointer dereference vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-10-14. KEV inclusion means the issue is considered known to be exploited in the wild, so defenders should treat it as an active risk rather than a routine patch item. The supplied corpus does not include affected version details, exploit mechanics, or sev [truncated]

Known exploited Microsoft CVE published 2025-10-06

CVE-2021-43226

CVE-2021-43226 is a Microsoft Windows privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2025-10-06. Because it is on the KEV list, defenders should treat it as a priority remediation item and follow Microsoft’s vendor guidance as well as CISA’s required action timeline.

Known exploited Microsoft CVE published 2025-10-06

CVE-2013-3918

CVE-2013-3918 is a Microsoft Windows out-of-bounds write vulnerability that CISA has placed in the Known Exploited Vulnerabilities (KEV) catalog. For defenders, the key takeaway is that this issue is not just theoretical: it is treated by CISA as a known-exploited Windows vulnerability, so exposed or unpatched systems should be prioritized for remediation.

Known exploited Microsoft CVE published 2025-10-06

CVE-2011-3402

CVE-2011-3402 is identified in the supplied source corpus as a Microsoft Windows remote code execution vulnerability and is listed by CISA in its Known Exploited Vulnerabilities catalog. The KEV record assigns a remediation due date of 2025-10-27 and directs defenders to follow vendor mitigation guidance. Because the corpus is limited, this debrief avoids inferring exploit mechanics, affected versions, or [truncated]

Known exploited Microsoft CVE published 2025-10-06

CVE-2010-3962

CVE-2010-3962 is a Microsoft Internet Explorer uninitialized memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That KEV listing makes this a defensive priority for any environment that still relies on Internet Explorer, especially where legacy systems or embedded dependencies make removal difficult. The supplied corpus does not provide a CVSS score or detailed [truncated]

MEDIUM Microsoft CVE published 2025-09-09

CVE-2025-53799

CVE-2025-53799 is a medium-severity local information-disclosure issue in Windows Imaging Component. Microsoft’s advisory and the NVD record indicate that an unauthorized attacker could disclose information on affected systems, with user interaction required.

CRITICAL Microsoft CVE published 2025-08-12

CVE-2025-53766

CVE-2025-53766 is a critical Microsoft vulnerability described as a heap-based buffer overflow in Windows GDI+ that can allow remote code execution over a network. The official NVD record assigns CVSS 3.1 9.8 and Microsoft’s advisory provides the affected build floors for Windows and Office branches. Given the no-interaction, network-reachable attack profile, this should be treated as an urgent patching item.

HIGH Microsoft CVE published 2025-08-12

CVE-2025-53732

CVE-2025-53732 is a Microsoft Office heap-based buffer overflow that can let an unauthorized attacker execute code locally. NVD rates the issue CVSS 7.8 (HIGH), and the vector indicates low attack complexity, no privileges required, user interaction required, and high impact to confidentiality, integrity, and availability. Because the weakness can lead to code execution, patching and exposure review shoul [truncated]

Known exploited Microsoft CVE published 2025-08-12

CVE-2013-3893

CVE-2013-3893 is a Microsoft Internet Explorer vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied corpus does not include exploit mechanics or a CVSS score, but it does confirm that the issue is treated as actively exploited and should be handled as a priority remediation item.

Known exploited Microsoft CVE published 2025-08-12

CVE-2007-0671

CVE-2007-0671 is a Microsoft Office Excel remote code execution vulnerability that CISA has listed in the Known Exploited Vulnerabilities catalog. The supplied corpus indicates active exploitation is significant enough to require prioritized remediation, with CISA directing organizations to apply vendor mitigations and to discontinue use of the product if mitigations are unavailable. Microsoft’s Security [truncated]

Known exploited Microsoft CVE published 2025-07-22

CVE-2025-49706

CVE-2025-49706 is a Microsoft SharePoint improper authentication vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on the day it was published. CISA marks it as known to be used in ransomware campaigns and directs defenders to urgently remove exposure from public-facing SharePoint Server installations that are end-of-life or end-of-service, including SharePoint Server 2013 and e [truncated]

Known exploited Microsoft CVE published 2025-07-22

CVE-2025-49704

CVE-2025-49704 is a Microsoft SharePoint code injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-07-22. CISA marks the issue as known to be used in ransomware campaigns and sets a remediation due date of 2025-07-23. Because it is a KEV-listed issue affecting SharePoint, organizations should treat exposure of public-facing deployments as urgent and follow CISA an [truncated]

Known exploited Microsoft CVE published 2025-07-20

CVE-2025-53770

CVE-2025-53770 is a Microsoft SharePoint deserialization of untrusted data vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-07-20. CISA marked it as having known ransomware campaign use and set a remediation due date of 2025-07-21. The published guidance prioritizes disconnecting public-facing SharePoint Server versions that are end-of-life or end-of-service, and follow [truncated]

HIGH Microsoft CVE published 2025-07-08

CVE-2025-49702

CVE-2025-49702 is a Microsoft Office type-confusion vulnerability with a high-severity CVSS 3.1 score of 7.8. According to the NVD record and Microsoft advisory, an unauthorized attacker can trigger local code execution on affected systems, but user interaction is required.

HIGH Microsoft CVE published 2025-07-08

CVE-2025-49697

CVE-2025-49697 is a Microsoft Office heap-based buffer overflow that can allow an unauthorized attacker to execute code locally. The issue was publicly published on 2025-07-08 and later updated on 2025-07-15. NVD rates it HIGH with a CVSS 3.1 score of 8.4, and Microsoft’s advisory is the key official remediation reference.

HIGH Microsoft CVE published 2025-07-08

CVE-2025-49696

CVE-2025-49696 is a Microsoft Office vulnerability described as an out-of-bounds read that may allow an unauthorized attacker to execute code locally. NVD assigns it CVSS 8.4 (HIGH) with local attack vector, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.

HIGH Microsoft CVE published 2025-07-08

CVE-2025-49695

CVE-2025-49695 is a high-severity use-after-free issue in Microsoft Office that can let an unauthorized attacker execute code locally. Because the impact is code execution with high confidentiality, integrity, and availability consequences, organizations should treat affected Office deployments as a patch priority.

HIGH Microsoft CVE published 2025-06-10

CVE-2025-47953

CVE-2025-47953 is a high-severity Microsoft Office vulnerability that can allow an unauthorized attacker to execute code locally. The supplied record describes the issue as a use-after-free condition, while NVD’s weakness mapping lists CWE-641; either way, the impact rating is severe because the CVSS vector indicates local attack conditions with no privileges or user interaction required and high confiden [truncated]

HIGH Microsoft CVE published 2025-06-10

CVE-2025-47167

CVE-2025-47167 is a high-severity Microsoft Office issue involving type confusion (CWE-843). According to the supplied official records, an unauthorized attacker can execute code locally. The CVSS 3.1 vector is AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a severe impact profile despite the local attack vector. The record was published on 2025-06-10 and last modified on 2025-07-09.

HIGH Microsoft CVE published 2025-06-10

CVE-2025-47164

CVE-2025-47164 is a high-severity use-after-free vulnerability in Microsoft Office that can allow an unauthorized attacker to execute code locally. Microsoft and NVD list a CVSS 3.1 score of 8.4 with local attack vector, no privileges required, and no user interaction required. The NVD entry marks multiple Microsoft Office product families as affected, including Office 2016, Office 2019, Office LTSC 2021/ [truncated]

HIGH Microsoft CVE published 2025-06-10

CVE-2025-47162

CVE-2025-47162 is a Microsoft Office heap-based buffer overflow that can allow an unauthorized local attacker to execute code. The NVD record rates the issue 8.4 (HIGH) and maps it to CWE-122, with affected products including Microsoft 365 Apps for enterprise, Office 2016, Office 2019, Office LTSC 2021, and Office LTSC 2024 variants listed in the record.

Known exploited Microsoft CVE published 2025-06-10

CVE-2025-33053

CVE-2025-33053 is a Microsoft Windows vulnerability described as an "External Control of File Name or Path" issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-10, with remediation due by 2025-07-01, which makes it a priority patching item for Windows environments. The supplied corpus does not provide impact specifics, so the safest response is to follow Microsoft’s guidance and [truncated]