Microsoft CVE Analysis

PortalFuse Quarterly Security Report

A comprehensive analysis of Microsoft Common Vulnerabilities and Exposures (CVEs) for Windows and Edge products, including severity ratings, attack vectors, and impact assessments.

Published: March 31, 2025 • For Period: January 2025 - March 2025

Table of Contents

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
    Conclusion

    Section 7

  8. 8
    Appendix

    Section 8

Executive Summary & Key Statistics

Executive Summary

During Q1 2025, PortalFuse analyzed 392 CVEs affecting Microsoft products, of which 9 were rated Critical and 260 Important, representing approximately 69% of disclosures in high-severity categories. The overall median Common Vulnerability Scoring System (CVSS) score stood at 7.8, with the most severe vulnerability reaching 9.9. This volume underscores sustained pressure on Microsoft’s Windows and Edge ecosystems to manage a consistently high throughput of serious flaws.

Remote Code Execution (RCE) and Elevation of Privilege (EOP) vulnerabilities dominated the threat landscape, accounting for 33% and 26% of all CVEs respectively. RCE remained the top impact type, while CWE-122 (Heap-Based Buffer Overflow) surfaced as the leading root cause. Despite the absence of zero-day “worst-case” exploits this quarter, these proportions highlight persistent exploit vectors that, if leveraged, could result in full system compromise or lateral movement within enterprise networks.

Practical exploitability analysis revealed that a subset of vulnerabilities exhibited low attack complexity and did not require user interaction, amplifying their attractiveness to adversaries. While publicly documented exploit code appeared for only a handful of cases, the potential for rapid weaponization in targeted campaigns remains elevated. This accentuates the need for defenders to prioritize monitoring and intrusion detection tuned to anomalous execution profiles, especially around Edge browser and Windows 11 24H2 x64 deployments—the most impacted product family this period.

On the remediation front, Microsoft’s patch cadence delivered a median patch time of 0 days, reflecting same-day release and mitigation for disclosed vulnerabilities. This performance indicates strong coordination between discovery and deployment phases, yet it also places a premium on enterprise change management processes to keep pace with near-instantaneous updates and avoid drift in protection posture.

Collectively, the data signal a robust but high-stakes security environment. The concentration of RCE/EOP flaws and the predominance of high-severity scores demand sustained investment in automated patch orchestration, runtime application self-protection, and proactive threat modeling. For executive leadership, the “so what” is clear: as Microsoft’s attack surface grows in complexity, strategic resilience hinges on continuous alignment of vulnerability management, threat intelligence, and operational agility to thwart evolving adversary tactics.

Section 2

Quarterly CVE Landscape: Volume, Severity, and Categorization

Explore the quarter's Windows and Edge CVE landscape, from the volume of new and updated threats to their severity and categorization. Key metrics and charts reveal overall trends in vulnerability reporting and classification.

Quarterly CVE Landscape: Volume, Severity, and Categorization

The "Quarterly CVE Landscape: Volume, Severity, and Categorization" section serves as the cornerstone for understanding the Microsoft vulnerability landscape for Windows and Edge products during this reporting period. Its primary objective is to provide a comprehensive, high-level statistical overview of all Common Vulnerabilities and Exposures (CVEs) analyzed. This includes an examination of the total volume of disclosures, their status as new or updated, the distribution across various severity levels, and an initial look at the types of vulnerabilities encountered.

For system administrators, security managers, and technical leadership, this section offers crucial baseline data. It helps quantify the scale of vulnerability management efforts required and identifies broad trends that inform resource allocation and strategic focus. By establishing these foundational metrics - such as the total number of CVEs, the proportion of high-severity issues, and the most common vulnerability categories - we create a clear context for the more detailed analyses presented in subsequent sections of this report. This data-driven snapshot is essential for grasping the overall scope and nature of the security challenges addressed by Microsoft this quarter.

The following analysis will present these descriptive statistics, supported by visualizations of monthly trends and category breakdowns, to paint a clear picture of the CVE landscape.


Overall CVE Volume and Disclosure Status

This quarter, a total of 392 Windows and Edge-specific CVEs were analyzed, indicating a substantial escalation in disclosure activity. Figure 1—depicting monthly trends in new versus updated CVEs—demonstrates that the vast majority of reported vulnerabilities were newly disclosed rather than updates to previous entries. In January, new CVEs far outpaced updated ones (198 versus 8), establishing the month as the most volatile of the quarter with the highest influx of fresh disclosures. February evidenced a significant decrease, with 83 new and 7 updated CVEs, while March experienced a modest rebound to 92 new cases and only 4 updates. Across the quarter, revisions remained a very small and diminishing fraction of total disclosures, underscoring the dynamic and emergent nature of the threat landscape. The predominance of new entries implies that security operations teams must continually adjust to novel vulnerabilities, with little reliance on incremental updates.

Severity Profile of Vulnerabilities

Turning to severity distribution, the landscape is notably weighted toward more serious vulnerabilities. This quarter, the combined percentage of Critical and High-Severity CVEs reached 68.6%, highlighting that over two-thirds of all reported vulnerabilities carry significant risk potential. Of these, only 9 CVEs were classified as Critical, while an overwhelming 260 were rated as Important (the data source’s ‘Important’ category aligns with standard ‘High’ severity definitions). The data from Figure 2, which charts monthly CVE volumes by severity, further clarifies this trend: High-severity issues dominated each month, peaking at 128 in January, dipping in February, and rising again in March. Medium-severity vulnerabilities declined precipitously from 70 in January to 24 in February, then held steady at 23 in March. Critical vulnerabilities were consistently minimal, registering just six in January and dropping to a single case by March. Low-severity CVEs were negligible throughout the quarter. The median CVSS (Common Vulnerability Scoring System) score for all vulnerabilities remained high at 7.8, reflecting a central tendency toward impactful security issues and mirroring the observed concentration of High and Critical designations.

Predominant Vulnerability Categories

The typology of vulnerabilities further underscores the operational risk profile for Microsoft environments. Figure 3, illustrating the distribution of CVEs by technical impact category, reveals that Remote Code Execution (RCE) is the most prevalent category, accounting for 131 cases (33%) of all vulnerabilities. Privilege Elevation follows closely with 103 instances (26%). These two categories together compose nearly 60% of the entire CVE landscape for Windows and Edge during this period, signaling an enduring adversarial focus on both initial compromise and the escalation of access within target environments. Other categories are notably less common: Denial of Service appears in 35 CVEs (9%), Information Disclosure and chromium-based security issues each register 31 cases (8%), while Security Feature Bypass and Spoofing round out the sub-10% categories at 7% each. The remaining classifications—‘None’ and Tampering—constitute only a nominal share, barely exceeding 1% collectively. This distribution demonstrates that the principal risk vectors this quarter are those that enable remote execution of malicious code or unauthorized elevation of privileges—threatening core system integrity and control.

Quarter-over-Quarter Context

From a longitudinal perspective, this quarter showcases substantial growth in reported vulnerabilities and severity concentration relative to the previous period. The total number of CVEs increased by 68.2% (a rise of 159 CVEs from last quarter), representing one of the sharpest escalations in recent cycles. Critical-severity CVEs rose by 50% (an absolute increase of 3), although their absolute numbers remain low. The proportion of Critical and High-severity vulnerabilities grew by 10.3%, further tilting the landscape toward higher risk. Notably, the number of Important (High-severity) CVEs nearly doubled, increasing by 87% (an additional 121 CVEs). The median CVSS score, while remaining essentially unchanged at 7.8, subtly reinforces the sustained weight of serious risk across the expanding CVE set.

Implications Within the CVE Landscape

The confluence of high volume, elevated severity, and a clear dominance of Remote Code Execution and Privilege Elevation issues characterizes this quarter as one of heightened exposure for Microsoft environments. The preponderance of new—rather than revised— CVEs signals a continuously evolving attack surface and the imperative for nimble vulnerability identification and remediation capabilities. The data reveals that attackers remain focused on vectors that provide rapid control or privilege escalation, reflecting the operational realities facing defenders.

Characteristics of Monthly CVE Dynamics

Examining monthly dynamics, January stands out with its pronounced spike in both overall CVEs and high-severity reports, creating a front-loaded workload for patch management and response teams. The subsequent reduction in February, followed by a moderate rebound in March, does not offset the overall surge in risk driven primarily by the influx of newly identified issues. Updated CVEs, by contrast, show a steady decline throughout the quarter, suggesting relatively lower re-prioritization pressure for historical vulnerabilities.

Severity and Category Interplay

The interrelationship between severity and vulnerability type is especially evident. Remote Code Execution and Privilege Elevation vulnerabilities dominate not only category counts but also disproportionately fall within the High and Critical severity brackets. This reinforces their relevance as top priorities in enterprise risk models and operational security processes. Meanwhile, less impactful categories and lower severity CVEs remain a secondary concern, both by volume and by potential for exploitation.

Data Coverage and Categorization Notes

Percentages presented for category distributions are calculated from CVEs that received explicit categorizations. A small number of entries were assigned as 'None' or lacked categorization, collectively constituting just over 1% of the dataset; this has a minimal effect on the overall representation of major vulnerability types. There is no significant evidence of data omission on a scale that would affect the strategic view afforded by this report.

Concluding Overview

In summary, the quarterly CVE landscape for Microsoft Windows and Edge products is marked by an elevated and expanding volume of disclosures, dominated by new and high-severity vulnerabilities. Remote Code Execution and Privilege Elevation remain the prevailing categories, together constituting nearly 60% of reported issues and dictating much of the risk narrative for the period. The overall trend is one of accelerating emergence of impactful vulnerabilities, highlighting the dynamic and high-stakes environment that system engineers and security managers must manage. This foundational overview sets the stage for deeper technical analysis and targeted discussion of key vulnerability classes in the sections that follow.

Total CVEs
392
increase 68.2%

Total vulnerabilities this quarter

Critical Count
9
increase 50.0%

Number of 'Critical' rated CVEs

High Count
260
increase 87.1%

Number of 'High' rated CVEs

% Critical & High CVEs
68.6 %
increase 10.3%

Most problematic CVEs this quarter

Median CVSS
7.8
decrease 0.0%

Typical CVSS score (out of 10)

Highest CVSS
9.9

Highest CVSS score (out of 10)

Top Vulnerability Category
Remote Code Execution

Most frequent vulnerability category

Most Affected Product(s)
Windows 11 24H2 X64

Windows Products with Highest CVE Count

Most Volatile Month
January

Month with most CVEs

Loading chart...
Figure 1. Trend of New vs. Updated Windows and Edge CVEs Published Monthly.
Chart Insight

New CVEs outnumber updated CVEs by a substantial margin in every month (January: 198 vs. 8; February: 83 vs. 7; March: 92 vs. 4). The highest influx of new CVEs occurs in January, followed by a sharp decline in February and a modest rebound in March. Updated CVE counts remain very low throughout the quarter and decrease steadily from eight in January to four in March. Overall, newly reported vulnerabilities drive the monthly CVE volume, while revisions constitute only a small and diminishing portion.

Loading chart...
Figure 2. Monthly Windows and Edge CVE Volume by Assessed Severity.
Chart Insight

High-severity CVEs consistently represented the largest share each month, peaking at 128 in January before falling to 61 in February and rising to 71 in March. Medium-severity counts declined sharply from 70 in January to 24 in February and remained essentially flat at 23 in March. Critical-severity CVEs were minimal and trended downward from six in January to two in February and one in March. Low-severity CVEs were negligible, registering one or zero per month throughout the period.

Loading chart...
Figure 3. Distribution of Windows and Edge CVEs by Vulnerability Category for the Quarter.
Chart Insight

Remote Code Execution vulnerabilities dominate the quarter’s CVE portfolio with 131 instances (33%), followed by Privilege Elevation at 103 CVEs (26%). All other categories fall below 10% individually, with Denial of Service at 9%, Information Disclosure and chromium-based each at 8%, and Security Feature Bypass and Spoofing both at 7%. The remaining ‘None’ and Tampering entries together account for just over 1% of the total. This distribution underscores that execution and elevation issues comprise nearly 60% of reported vulnerabilities in the period.

Summary

The “Quarterly CVE Landscape: Volume, Severity, and Categorization” section provides a comprehensive statistical snapshot of vulnerability disclosures affecting Microsoft Windows and Edge products during the first quarter of 2025. The analysis meticulously tracks the evolution of vulnerability trends through key metrics—total volume, disclosure status, severity levels, and technical categorization—emphasizing the prevalence of fresh vulnerabilities. This high-level overview establishes a critical context for understanding both the immediate and broader security implications for operational teams.

The data reveal a marked surge in vulnerability disclosures, with a 68.2% increase in total CVEs compared to the previous quarter. Over two-thirds of these vulnerabilities have been identified as Critical or High severity, with the median Common Vulnerability Scoring System (CVSS) score confirming the substantial risk profile. Notably, Remote Code Execution and Privilege Elevation issues dominate the landscape, jointly accounting for nearly 60% of the CVEs. Such concentration of high-severity vulnerabilities necessitates agile response mechanisms and targeted defensive strategies, underlining the operational demands placed on vulnerability management and patch deployment processes.

Overall, the findings underscore the dynamic and high-stakes nature of the threat landscape during this period, driven predominantly by a surge in new, impactful vulnerabilities. This evolving risk environment calls for continuous enhancement of monitoring and mitigation practices to prevent unauthorized control and escalation attempts. As this section draws to a close, the robust data-driven insights presented here lay the groundwork for subsequent analyses that will delve deeper into the technical nuances and operational imperatives shaping the broader security strategy.

Section 3

Attack Surface Analysis: Exploitability & Access

Analyze the evolving attack surface by examining vulnerability exploitability, including attack vectors, privilege requirements, user interaction, and overall complexity. Discover how these factors shape the risk profile and highlight common...

Attack Surface Analysis: Exploitability & Access

The "Attack Surface Analysis: Exploitability & Access" section moves beyond theoretical severity scores to delve into the practical, real-world exploitability of vulnerabilities identified this quarter. While a CVSS score provides a standardized measure of severity, it does not always capture the full operational context. To truly understand risk, security teams must analyze the "attack surface"—the specific pathways and conditions that an adversary could leverage. This analysis is designed to equip administrators to move from a reactive to a proactive security posture, allocating finite resources to the most probable and impactful threats. An exploit requiring network access, no user interaction, and no special privileges, for instance, presents a far more immediate and widespread danger than one requiring local access and user complicity.

To build this nuanced understanding, we will dissect four key dimensions of exploitability: - Attack Vectors: The pathways through which vulnerabilities can be attacked (e.g., Network, Local, Adjacent Network, Physical). Network-based vectors are typically of highest concern due to their potential for remote exploitation. - Privileges Required: The level of system access an attacker needs before they can exploit the vulnerability (None, Low, or High). Vulnerabilities requiring 'None' are particularly dangerous. - User Interaction: Whether a legitimate user must take some action (e.g., click a link, open a file) for the exploit to succeed ('Required') or if the vulnerability can be exploited directly by the attacker ('None'). - Attack Complexity: The conditions beyond the attacker's control that must exist for an exploit to succeed ('Low' or 'High'). 'Low' complexity means fewer hurdles for the attacker.

By examining these factors both individually and in combination, we aim to paint a clear, actionable picture of this quarter's threat landscape. The following data and visualizations will guide this exploration, building from foundational metrics to a synthesized view of operational risk.

The first visualization, Distribution of Attack Vectors, presents a high-level overview of how vulnerabilities are accessed across the Microsoft ecosystem this quarter. Network-based attack vectors represent the largest proportion at 50%, confirming their dominant role in the attack surface. Local access accounts for 38.5%, making it the second most prevalent vector. In contrast, physical attack vectors constitute 8.2%, while adjacent network attacks are rare, comprising only 2.3% of CVEs. Notably, the combined share of network and local vectors encompasses approximately 88.5% of all vulnerabilities, indicating that most attack scenarios remain focused on remote and local code paths rather than physical access or proximity-based exploits. This distribution underscores that defenses for both network-exposed assets and locally accessible components must remain primary priorities for system administrators and defenders.

Building upon this, the Attack Vectors by Privileges Required chart clarifies how much pre-existing access an adversary must already possess to exploit vulnerabilities across these vectors. For network-based vulnerabilities—the most critical from an exposure standpoint—the vast majority are exploitable with no privileges: 175 out of the 196 total network vector CVEs require no prior access, only 19 require low-level access, and a mere 2 necessitate high-level privileges. This trend is echoed across adjacent network vulnerabilities, with 8 out of 9 requiring no privileges. By contrast, the local access vector tells a different story: most local vulnerabilities (91 of 151) require an attacker to have already attained low privileges, with 53 not requiring any and just 7 necessitating high privileges. Physical vectors similarly skew toward low (22) or no privileges (10), with none demanding high privileges. The clear implication is that the attack surface remains dominated by vulnerabilities accessible remotely or with little to no required foothold—an acute risk for perimeter systems and services.

The Category vs. Attack Vectors & Privileges chart dissects these findings further by mapping distinct vulnerability types (categories) against their likely exploitation paths and privilege requirements. The most consequential pattern emerges within Remote Code Execution (RCE) vulnerabilities: a pronounced concentration exists where exploits are both network-deliverable and require no privileges (77 CVEs). This is more than double the next highest individual pairing and signifies an elevated operational risk, especially for high-value targets like identity management and federated systems. In comparison, Elevation of Privilege (EoP) vulnerabilities cluster around local vectors with low privileges (64 CVEs), reflecting internal threats and post-compromise lateral movement scenarios. Other categories, including Denial of Service and Information Disclosure, have smaller and more dispersed distributions across vector-privilege pairs, indicating varied exploit prerequisites and a more fragmented risk profile.

The analysis progresses with the Category vs. User Interaction & Complexity chart, revealing how user involvement and inherent exploit difficulty shape risk within each vulnerability class. RCE CVEs lead across all categories with 131 total entries, predominantly skewed to cases requiring user action (89 low-complexity, user-action-required flaws). However, Privilege Elevation vulnerabilities most often exhibit low complexity and require no user interaction (73 CVEs), highlighting streamlined exploitation pathways for attackers landing on local systems. Similar low-complexity, no-user-interaction patterns are observed in Denial of Service and Information Disclosure categories, which accumulate 30 and 21 such CVEs, respectively. Spoofing, on the other hand, is nearly exclusive to low-complexity exploits requiring user interaction (24 CVEs). The dominance of low complexity across most categories (85.5% of all CVEs are low complexity, up 5.4% from last quarter) signals that the majority of vulnerabilities can be exploited with straightforward methods, placing a heavy burden on detection, prevention, and user awareness.

The CVE Risk Chart synthesizes all aforementioned exploitability dimensions, overlaying each CVE's risk profile onto a radial plot where proximity to the center signifies higher operational risk. Most CVEs cluster within the High-risk ring, denoting that when factors like remote access, user independence, low complexity, and privilege escalation potential are combined, the result is a dense aggregation of severe threats. The Medium-risk perimeter contains fewer, lower-impact vulnerabilities, while the Critical and Low rings are comparatively sparse. Bubble size—corresponding to CVSS score—also grows closer to the core, reinforcing the correlation between exploitability characteristics and underlying technical severity. This consolidated visualization is critical for prioritizing patching and mitigative efforts, enabling stakeholders to focus on those vulnerabilities where every aspect of the attack chain maximizes the potential harm to the organization.

To operationalize the concept of "ease of exploit," the report calculates the count of vulnerabilities meeting the strictest "worst-case" criteria: network-accessible, no user interaction, no required privileges, low attack complexity, and high CVSS score. For this quarter, this metric reveals a total of zero CVEs fitting every element of this most alarming scenario—an encouraging outcome in the context of defense-in-depth, as it suggests attackers must bypass at least one hurdle (user interaction, prior privilege, or higher complexity) to fully compromise organizational assets. Nevertheless, the persistence of large numbers of network/no-privilege/low-complexity vulnerabilities just outside this combination remains a cause for continued vigilance.

Synthesizing across all exploitability metrics, several themes define this quarter's attack surface. The overwhelming prevalence of network-based vulnerabilities requiring no privileges establishes the principal threat vector for Microsoft environments, particularly where identity, access management, and federated authentication are concerned. The majority of RCE flaws—among the most damaging from a business continuity and confidentiality standpoint—are readily exploitable remotely and without pre-existing system access, often requiring only minimal user engagement. Privilege Elevation risks, while more commonly tied to local access, add pressure to internal monitoring and least-privilege enforcement. The expansive presence of low-complexity vulnerabilities across all major classes amplifies the imperative for rapid threat detection and remediation, as attackers need invest little effort in overcoming technical hurdles. Collectively, these trends accentuate the importance of defense strategies attuned not just to abstract severity metrics, but to the practical, real-world conditions that elevate a vulnerability from theoretical concern to immediate enterprise risk.

Network Vector
50.0 %
increase 4.0%

% of Network Vector CVEs

Adjacent Vector
2.3 %
decrease 51.4%

% of Adjacent Network Vector CVEs

Local Vector
38.5 %
increase 21.3%

% of Local Vector CVEs

Physical Vector
8.2 %
decrease 34.4%

% of Physical Vector CVEs

Low Privileges Required
33.9 %
increase 1.4%

% of Low Privileges Required CVEs

High Privileges Required
2.3 %
decrease 33.1%

% of High Privileges Required CVEs

Low Attack Complexity
85.5 %
increase 5.4%

% of Low Attack Complexity CVEs

High Attack Complexity
13.5 %
decrease 14.9%

% of High Attack Complexity CVEs

User Action Required
48.5 %
increase 36.1%

% of User Action Required CVEs

High Risk CVEs
0
±0.0%

Weighted score (network + low complexity + low privileges + no interaction)

Loading chart...
Figure 4. Distribution of Attack Vectors for Windows and Edge CVEs.
Chart Insight

Network-based attack vectors constitute the largest share at 50% of total CVEs. Local vectors follow at 38.5%, representing the second-most common access path. Physical attacks account for 8.2% of CVEs, while adjacent-network vectors are the least common at 2.3%. Together, network and local vectors comprise roughly 88.5% of the distribution.

Loading chart...
Figure 5. Breakdown of Attack Vectors by Privilege Requirements for Windows and Edge CVEs.
Chart Insight

Network-based CVEs overwhelmingly require no privileges, with 175 of 196 network vulnerabilities needing no privileges and only 19 and 2 CVEs requiring low or high privileges, respectively. Adjacent-network exploits similarly skew toward no privileges (8 of 9 CVEs). By contrast, local attack vectors predominantly require low privileges (91 of 151 CVEs) versus 53 that need no privileges and 7 that need high privileges. Physical exploits also favor low privileges (22 vs. 10 no-privilege cases) and include no high-privilege instances.

Loading chart...
Figure 6. Privilege Requirements for Attack Vectors within each Vulnerability Category for Windows and Edge CVEs.
Chart Insight

Remote Code Execution (RCE) vulnerabilities are overwhelmingly delivered over the network with no privileges required, accounting for 77 CVEs—more than double the next highest individual pairing. The next most significant concentration is Privilege Elevation via the local vector with low privileges, at 64 CVEs. All other CVE categories exhibit substantially lower counts across their respective attack vectors and privilege levels.

Loading chart...
Figure 7. Attack Complexity by User Interaction within each Vulnerability Category for Windows and Edge CVEs.
Chart Insight

Remote Code Execution leads all categories with 131 CVEs—primarily driven by the 89 low-complexity flaws that require user action—while Privilege Elevation follows at 103 CVEs, mostly low-complexity exploits needing no user interaction (73). Across all six categories, low-complexity attacks substantially outnumber high-complexity ones, and “No User Action” dominates in Privilege Elevation, Denial of Service, and Information Disclosure, whereas Remote Code Execution and Spoofing show higher counts under “User Action Required.” Denial of Service and Information Disclosure both exhibit a strong skew toward low-complexity, no-interaction exploits (30 and 21 CVEs, respectively), and Spoofing is almost exclusively low-complexity with user action (24 CVEs). Tampering is a notable outlier with only a single high-complexity, user-action-required CVE.

Loading chart...
Figure 8. CVE Risk Chart. This chart displays CVEs based on a risk score and jittered within a risk ring for Windows and Edge CVEs.
Chart Insight

The vast majority of CVEs cluster in the High-risk ring, with noticeably fewer in the Medium ring and only a handful in the Critical and Low rings. Bubbles in the Critical and High rings are generally larger—reflecting CVSS scores in the 8–10 range—whereas Medium-ring bubbles are smaller (CVSS ~5–7) and the few Low-ring markers are minimal. There are no prominent large-bubble outliers in the Medium or Low rings. Overall, bubble size (CVSS score) increases systematically toward the center, aligning higher severity with inner risk rings.

Summary

The "Attack Surface Analysis: Exploitability & Access" section provides a comprehensive evaluation of the practical risks posed by vulnerabilities during the quarter. The analysis underscores that network-based vulnerabilities remain the predominant risk, with 50% of CVEs being exploitable remotely and predominantly not requiring any privileges. Additionally, while local access vulnerabilities constitute a significant fraction at 38.5%, their need for at least low-level permissions somewhat mitigates immediate external threat potential. The detailed breakdowns by attack vectors, privilege requirements, user interaction, and complexity further reveal that the majority of identified CVEs feature low attack complexity, enabling attackers to exploit these vulnerabilities with minimal operational barriers.

Overall, these findings highlight the critical need for strengthened perimeter defenses, enhanced identity and access management, and diligent monitoring of both remote and local threat vectors. Despite the absence of worst-case CVEs—vulnerabilities meeting the strictest combination of exploitability conditions—the data indicate that the prevalent network-based, no-privilege, low-complexity vulnerabilities continue to demand vigilant mitigation efforts. This conclusion reinforces the imperative for proactive, context-aware security measures as we transition towards the subsequent segments of the report.

Section 4

Deep Dive: CVSS Insights & Prioritization Hotspots

Gain deeper insights into CVSS scores and their distribution across vulnerability categories, identifying common weaknesses (CWEs) linked to high-risk Windows and Edge CVEs. Pinpoint prioritization hotspots by understanding the correlation...

Deep Dive: CVSS Insights & Prioritization Hotspots

In the "Deep Dive: CVSS Insights & Prioritization Hotspots" section, we shift our focus from the pathways of exploitation to the intrinsic severity and root causes of this quarter's vulnerabilities. While understanding the attack surface is crucial, a comprehensive risk assessment also requires dissecting the Common Vulnerability Scoring System (CVSS) scores and their distribution. A high average severity score can be misleading if it masks a wide variance; conversely, a category with a narrow range of consistently high scores signals a uniformly dangerous group of vulnerabilities.

Furthermore, this analysis drills down into the underlying software flaws by examining the most frequent Common Weakness Enumerations (CWEs). Identifying recurring CWEs is fundamental to proactive defense. It moves the focus from patching individual vulnerabilities to addressing systemic weaknesses in code and architecture, ultimately preventing future issues.

By exploring CVSS score distributions and spotlighting prevalent CWEs, this deep dive provides technical teams with the nuanced data needed for sharp risk prioritization and strategic defense planning.


A high-level assessment of CVSS severity patterns this quarter reveals stark disparities across vulnerability categories (Figure: CVSS Score Distribution by Category). Boxplot visualizations distinctly illuminate both the central severity tendencies and the underlying volatility for each category. The Interquartile Range (IQR) of each box represents the middle 50% of scores, providing insight into score clustering, while whiskers denote the overall range. The median—a crucial metric demarcated by a line within the box—anchors evaluations of typical severity.

Remote Code Execution (RCE) vulnerabilities overwhelmingly dominate the upper echelons of risk, with a median CVSS Base Score near 8.8 and a spread from approximately 6.5 up to 9.8. This range, the broadest observed among all categories, is punctuated by multiple high-end outliers at 9.8, underscoring a density of exceptionally critical threats. Notably, the 90th percentile (P90) CVSS score for the entire dataset registers at 8.8, while the highest single score, 9.9, marks an upper boundary influenced by several RCE entries. This heavy skew toward high and even critical values among RCEs reflects the elevated risk of full system compromise—particularly acute for highly interconnected Microsoft platforms, such as Entra ID and Defender.

Privilege Elevation vulnerabilities, with a median score around 7.8, present a somewhat narrower distribution than RCEs but are still subject to sporadic critical outliers reaching 9.8. Security Feature Bypass, by contrast, spans from 4.3 to 8.8 and centers at a median of approximately 6.5, highlighting more moderate but variably distributed risk. Denial of Service clusters tightly around a median of 7.5, with a compact IQR, suggesting a more predictable (albeit still notable) impact compared to the volatility seen in RCEs. Lower-severity categories, such as Information Disclosure (median ≈5.9) and Spoofing (median ≈6.3), collectively reside below the overall dataset median of 7.8. Tampering is represented by a solitary entry at 6.8, insufficient for broader trend analysis.

The observed variability—especially within RCE—highlights the inadequacy of mean severity as a solitary risk metric. The wide IQRs and presence of extreme outliers compel technical teams to adopt a risk lens that accounts for both volume and peak criticality. This is acutely relevant given the prominent callouts indicating that the most significant outliers correspond with vulnerabilities in high-value, network-exposed components of Microsoft’s identity and remote access ecosystem.

Drilling deeper, the analysis of root cause patterns via Common Weakness Enumeration (CWE) reveals the overwhelming dominance of memory safety issues. Of all mapped vulnerabilities, memory safety weaknesses account for 174 entries, a 68.9% increase quarter over quarter—by far the most significant growth among tracked categories. More significantly, the top three CWEs comprise 48.3% of all mapped CVEs, though this concentration dropped by 4.0 percentage points from last quarter, indicating a slight diversification in weakness types even as memory issues remain prevalent.

CWE-122 (Heap-based Buffer Overflow) emerges as the single most frequent and impactful weakness, appearing roughly twice as often as the next most common types. It almost exclusively drives high and critical severity CVEs, frequently intersecting with network-exploitable RCE and Elevation of Privilege vulnerabilities. This pattern is visually reinforced in the 'CVSS Distribution by Attack Vector for Top CWEs' chart. There, each panel examines a specific top CWE, charting its CVSS score distribution as segmented by attack vector (Network, Local, Physical, Adjacent). For CWE-122, network-context exploits consistently exhibit scores clustered between 8.8 and 9.8, illustrating a dangerous blend of exploitability and severity—a risk amplified in Microsoft’s telephony and Defender components, as underscored by multiple callouts.

Examining additional top weaknesses, CWE-416 (Use After Free) and CWE-125 (Out-of-bounds Read) appear as secondary but still consequential. For CWE-416, network-exploitable cases likewise cluster at the higher end of the CVSS scale, with several outliers at the critical threshold (9.8), evidencing their systemic danger in RCE and privilege escalation scenarios. Local context for CWE-416 features a narrower spread, mostly in the 7–7.8 range, indicating reduced but still significant risk where user interaction or lateral movement is required.

CWE-125 demonstrates pronounced context dependency: network-based exploitation yields CVSS medians at or above 8.8, while local and physical vectors display both lower medians and a broader distribution, occasionally dipping near 4.3. This highlights the critical need to contextualize severity by both root cause and attack vector, as identical weakness classes can yield vastly different operational threats depending on exposure.

Improper Access Control (CWE-284) rounds out the top set, though its distribution is notably bimodal. While some network instances spike to critical (9.8) and high (8.8) severity, a substantial number appear at moderate to low levels when local exploitation is required—such as in privilege escalation through desktop components or service misconfigurations.

A cross-category synthesis reinforces several prioritization hotspots. The intersection of network-exploitable RCE and privilege elevation vulnerabilities—overwhelmingly rooted in heap-based buffer overflows and use-after-free memory errors—constitutes the most pressing and systematically damaging threat vector this quarter. This risk profile is amplified by the acute clustering of high CVSS scores in these groups and the direct implications these flaws have on systems with broad identity and remote access integration, such as Microsoft Entra ID and Defender infrastructure.

Across all mapped CVEs, configuration, cryptographic, and logic/state weaknesses are either entirely absent or appear at negligible levels, with the exception of a minor presence of race conditions. This further underscores an entrenchment of legacy and new flaws in memory safety domains—a challenge compounded by the continued increase in both frequency and severity.

Minimal variability in the quarter-over-quarter metrics for median and P90 CVSS scores suggests that systemic risk remains consistently high and is not being offset by the observed (albeit minor) diversification of CWE types. The addition of new weakness types this quarter is negligible, emphasizing that core risk remains firmly anchored in long-standing memory management issues.

In summary, the granular analysis of CVSS distributions, IQRs, and underlying CWEs for this quarter sharpens the understanding of risk concentration within Microsoft’s vulnerability landscape. RCE and privilege escalation vulnerabilities, particularly those stemming from memory safety flaws (notably CWE-122), exhibit the highest and most volatile severity profiles—especially when remotely exploitable. This pattern, coupled with the comparative stasis in other categories and the lack of significant emergence of novel weakness types, highlights the continued need for memory safety as the epicenter of defensive vigilance and risk triage in Microsoft environments.

cwe category distribution
memory_safety=174
race_concurrency=5
improper_access_control=29
input_validation_injection=22
cryptographic_issues=0
configuration_weakness=0
logic_state_errors=0
none=185
Median CVSS
7.8
decrease 0.0%

Typical CVSS score (out of 10)

P90 CVSS
8.8
decrease 0.0%

90th percentile CVSS score

Highest CVSS
9.9

Highest CVSS score (out of 10)

Top Common Weakness
CWE-122

CWE with highest % of total CVEs

Top 3 CWEs Coverage
48.3 %
decrease 4.0%

Percent of total CVEs covered by top 3 CWEs

Memory Safety Bugs
174
increase 68.9%

Number of memory safety bugs

Logic State Errors
0
±0.0%

Number of logic state errors

Loading chart...
Figure 9. Box Plots of CVSS Scores per Category.
Chart Insight

Remote Code Execution vulnerabilities exhibit the highest median CVSS Base Score (≈8.8) and the broadest overall range, spanning roughly 6.5 to 9.8 with multiple high-end outliers at 9.8. Privilege Elevation has a median around 7.8 with one extreme outlier at 9.8, while Security Feature Bypass covers scores from about 4.3 to 8.8 (median ≈6.5). Denial of Service clusters around a median of 7.5 with a tighter interquartile range, and Information Disclosure and Spoofing both center below 7 (medians ≈5.9 and ≈6.3, respectively). Tampering appears as a single data point near 6.8.

Loading chart...
Figure 10. CVSS Distribution by Attack Vector for Top CWEs affecting Windows and Edge CVEs.
Chart Insight

CWE-122 (Heap-based Buffer Overflow) dominates the high and critical severity CVEs, accounting for the largest proportion of entries by a substantial margin. It appears roughly twice as often as the next most frequent weaknesses, CWE-416 (Use After Free) and CWE-125 (Out-of-bounds Read). The other CWEs in the top list—CWE-284 (Improper Access Control) and CWE-400 (Unknown)—each have markedly fewer occurrences. Overall, the distribution is heavily skewed toward CWE-122 relative to all other reported CWEs.

Summary

In this section, we provided a detailed examination of CVSS score distributions across vulnerability categories and an in-depth analysis of prevalent Common Weakness Enumerations (CWEs) to move beyond simple averages of severity. The analysis revealed that Remote Code Execution (RCE) vulnerabilities exhibit the highest and most volatile score range, with a median CVSS around 8.8 and multiple upper-end outliers near 9.8, indicating a significant concentration of critical threats. The focused evaluation of percentiles and interquartile ranges underscored the necessity of considering both average severity and extreme score deviations when assessing risk.

The scrutiny of the underlying CWEs further identified memory safety issues—particularly CWE-122 (Heap-based Buffer Overflow)—as the dominant factor driving high-severity vulnerabilities, notably in network-exploitable scenarios across key Microsoft platforms like Entra ID and Defender. Although minor shifts in CWE diversity were observed, the persistent concentration in memory-related failures implies an ongoing systemic risk. These insights reinforce the need for refined risk assessment and prioritization strategies and set the stage for continued exploration of emerging trends and mitigation measures in subsequent sections.

Section 5

Product Impact & Remediation Timeliness

Assess the impact of vulnerabilities on specific Windows and Edge products and the timeliness of remediation, highlighting the most affected software by CVE criticality. Understand patching and disclosure timelines through an analysis of NVD...

Product Impact & Remediation Timeliness

The "Product Impact & Remediation Timeliness" section shifts the analytical focus towards the tangible impact of vulnerabilities on specific Microsoft products and product families, and critically examines the timeliness of the remediation and disclosure lifecycle. Understanding which products are most frequently targeted or harbor the most severe vulnerabilities is essential for resource allocation in patching and system hardening. For instance, a high concentration of critical CVEs in widely deployed server products demands immediate attention from administrators.

Equally important is the timeliness aspect. The period between a vendor releasing a patch and the vulnerability details being publicly cataloged (e.g., in the National Vulnerability Database - NVD) represents a window of potential exposure where systems might be patched but full public awareness and standardized scoring are still pending. Conversely, delays in patching vulnerabilities that are already publicly known (or worse, exploited) increase risk. This section will analyze metrics such as the median days to NVD publication and the percentage of CVEs disclosed by NVD within critical timeframes post-vendor patch.

This analysis of product impact and disclosure/patching timeliness provides system administrators and security teams with actionable intelligence for prioritizing their efforts and understanding the dynamics of the vulnerability management ecosystem for Microsoft products.

Most Impacted Products and Versions

During the first quarter of 2025, Windows 11 editions emerged as the most impacted product family, with the Windows 11 24h2 x64 release registering the highest count of vulnerabilities among all evaluated Microsoft products. Specifically, Windows 11 24h2 x64 experienced 113 High-severity CVEs and 3 classified as Critical. Other Windows 11 x64 variants—namely, 23h2 and 22h2—also recorded elevated vulnerability counts, both with 110 High-severity CVEs and 2 Critical each. This trend starkly contrasts with Windows 10 releases, which reported only 39 to 44 High-severity CVEs per edition and a single Critical CVE each for their top versions. Microsoft Edge (Chromium-based) presented substantially lower impact, with 29 High-severity and zero Critical vulnerabilities. A notably anomalous entry, labeled as “Unknown Product Version,” accounts for 6 Critical and 100 High-severity CVEs—likely reflecting data aggregation challenges or reporting artifacts.

The concentration of high- and critical-severity CVEs in Windows 11 editions, as visualized in Figure X (“Top Affected Products by CVE Criticality”), signals a sharply expanding attack surface aligned with increased enterprise migration to Windows 11. This pattern raises the potential risk profile for environments where Windows 11 adoption is accelerating and emphasizes the product’s strategic significance for vulnerability management.

Timeliness of NVD Publication Relative to Vendor Patch

Assessment of the CVE disclosure and public cataloging process demonstrates a continued trend of near-simultaneous patch release and NVD publication throughout the quarter. The metric median_days_to_patch stood at 0.0 days, indicating that, for at least half of the vulnerabilities tracked, the NVD public listing coincided with or occurred on the same day as the vendor patch release. This represents no change from the previous quarter and demonstrates consistency in Microsoft’s patch disclosure pipeline.

Evaluating the proportion of vulnerabilities whose details appeared in the NVD shortly after the vendor patch, 93.6% of CVEs were published within 7 days (patched_le_7d_pct), and an even higher 96.7% reached publication within 30 days (patched_le_30d_pct). While the fraction of CVEs published within 30 days increased by 1.8 percentage points compared to the prior quarter, the within-7-days percentage saw a marginal decrease of 0.8 points, signifying relative stability in overall disclosure performance.

Despite this efficiency, no evidence surfaced of NVD publication acceleration for higher-severity CVEs. According to Figure Y (“NVD Publication Delay by CVE Severity”), the median “days to NVD” stands at zero across all severity levels—Critical, High, Medium, and Low. The boxplots reveal that while some Medium and High cases span a wider publication window (from approximately three days before to two days after patch issuance), Critical CVEs do not receive prioritization in NVD cataloging, contradicting the assumption that more severe issues are universally published faster.

Impact of Disclosure Timeliness by Severity

The uniformity of NVD publication timelines, irrespective of severity, has material implications. For administrators managing identity and endpoint solutions such as Microsoft Entra ID and Defender for Endpoint—core components in the Windows 11 ecosystem—the lack of expedited public disclosure for critical vulnerabilities can impede rapid third-party risk assessment. This temporal disconnect, repeatedly observed in both empirical statistics and visualized data, underlines the continued reliance administrators must place on internal security telemetry during the period between patch issuance and broader public awareness.

Analysis of “Zero-Day” Exposure

During this analysis period, explicit metrics concerning “zero-day” CVEs—that is, those exploited before or on the day of public patch or NVD disclosure—are unavailable or not indicated as significant. No pronounced trend or outlier was observed in terms of publicly exploited, unpatched, or patch-day-exploited CVEs. As a result, this report does not identify any material escalation of “zero-day” risk but will continue to monitor this dimension in subsequent periods.

Quarter-over-Quarter Timeliness Trends

Scrutiny of quarter-over-quarter trends reveals a continuation of established patterns in patch-to-public-disclosure windows. The median_days_to_patch remained unchanged at 0.0 days, with the percentage of CVEs cataloged within 7 days showing only a minor decrease of less than one percentage point. The share of vulnerabilities disclosed within 30 days increased slightly, by 1.9%. These small-scale fluctuations are not indicative of major systemic shifts but reinforce the relative stability and predictability of Microsoft’s vulnerability disclosure cadence.

Considerations for Systems Administrators

For system administrators, several important considerations arise from this quarter’s data:

  • The continued and escalating concentration of high-severity CVEs in Windows 11 requires prioritization of this product line in patch management workflows. Systems running Windows 11—particularly 24h2, 23h2, and 22h2 x64 editions—face the greatest exposure based on current reported vulnerabilities.
  • Patch availability closely tracks public awareness, with nearly all Microsoft CVEs reaching the NVD within a week of patch issuance. This enables timely prioritization for patch deployment but means that there is limited grace period for exploitation before vulnerabilities become widely known.
  • However, the lack of accelerated NVD publishing for Critical or High-severity vulnerabilities means that administrators cannot depend on disclosure severity as an external indicator for urgency during the initial days after a patch is released.

Concluding Analysis

In summary, the first quarter of 2025 saw Windows 11 editions, most notably version 24h2 x64, lead all Microsoft product lines in both the number and severity of reported CVEs. While the bulk of vulnerabilities were addressed with rapid patch release and disclosure timelines—demonstrated by a median zero-day delay between patch and NVD publication—the absence of prioritization for severe vulnerabilities in public cataloging remains unchanged. Administrators should recognize that, although patch release is highly synchronized with public disclosure, the density of high-severity vulnerabilities in core platforms like Windows 11 increases both the urgency and the complexity of maintaining secure environments.

Collectively, these findings underscore a stable but challenging environment for Microsoft customers: while public vulnerability awareness is generally prompt, product-specific risk—especially within Windows 11—continues to grow. Meticulous patch management, focused specifically on the most affected products and attentive to rapidly evolving threat landscapes, remains the essential posture for security teams during this continued transitionary period in enterprise endpoint modernization.

Most Affected Product(s)
Windows 11 24H2 X64

Windows Products with Highest CVE Count

Typical Patch Delay
0.0
±0.0%

Median number of days to patch

Patched within 7 days
93.6 %
decrease 0.9%

% of CVEs patched within 7 days

Patched within 30 days
96.7 %
increase 1.9%

% of CVEs patched within 30 days

Loading chart...
Figure 11. Products with Highest Counts of Critical/High CVEs for Windows and Edge.
Chart Insight

Windows 11 editions dominate high‐severity CVE counts, with 24h2 x64 at 113 and both 23h2 and 22h2 x64 at 110, compared to Windows 10 releases, which range from 39 to 44, and Microsoft Edge with 29. Critical CVEs are uniformly low across named products (0–3 per edition), with the exception of the “Unknown Product Version” category which has six. Medium/Low severity CVEs also peak in Windows 11 (73–74) versus 23–26 in Windows 10 and 24 in Edge. Overall, Windows 11 releases stand out with substantially more high‐severity vulnerabilities than other top‐affected products.

Loading chart...
Figure 12. Days from Vendor Patch to NVD Publication, by Severity for Windows and Edge. Negative scores may indicate: 1) CVE revision after initial publication; 2) independent third-party NVD submissions prior to notifying Microsoft.
Chart Insight

All four severity levels share a median “days_to_nvd” of zero, indicating no clear acceleration of NVD publication for higher-severity CVEs. The Medium and High boxes exhibit the greatest overall span in whisker length (roughly –3 to +2 days for Medium and –6 to +2 days for High), while Low and Critical show virtually no interquartile range. A single extreme negative outlier at –540 days appears in the Critical category, consistent with a CVE revision or third-party NVD submission artifact rather than an actual pre-publication patch. No systematic decrease in publication delay is observed as severity increases.

Summary

The "Product Impact & Remediation Timeliness" section detailed the effects of high-severity vulnerabilities on specific Microsoft product lines, with a clear emphasis on the escalating exposure in Windows 11 environments. The analysis revealed that Windows 11 editions—especially version 24h2 x64—account for a significant proportion of high and critical CVEs, underscoring a widening attack surface as more enterprises transition from previous Windows versions. In parallel, the examination of remediation timeliness indicated that while the NVD publication occurs almost simultaneously with vendor patch releases (median delay of 0.0 days), there remains a consistent lack of prioritization for higher-severity vulnerabilities. This uniformity in disclosure timing, alongside marginal fluctuations in the percentage of vulnerabilities published within 7 and 30 days, suggests that internal measures and rapid patch deployment remain pivotal despite limited external signal differentiation.

Collectively, these findings illustrate a stable yet challenging security landscape where the increased vulnerability density in Windows 11 demands concentrated patch management and enhanced internal risk detection mechanisms. The consistency in patch-to-disclosure cadence reinforces the need for proactive monitoring and strategic hardening of endpoint and identity management defenses. As this analysis concludes, the focus now naturally shifts towards a deeper examination of evolving threats and adaptive security strategies in ensuing sections.

Section 6

Spotlight: This Quarter's Most Critical Vulnerabilities

Spotlight the quarter's most critical Windows vulnerabilities, offering detailed insights and CVSS scores for high-impact threats. Visualizations help uncover distinct patterns and shared characteristics among these significant issues, aiding in...

Spotlight: This Quarter's Most Critical Vulnerabilities

The "Spotlight: This Quarter's Most Critical Vulnerabilities" section provides a focused examination of a curated list of the most critical and potentially impactful Microsoft Windows vulnerabilities disclosed during this reporting period. While previous sections have analyzed broad trends and distributions, this spotlight aims to draw specific attention to individual CVEs that warrant heightened awareness due to their inherent severity, ease of exploitation, or observed activity in the threat landscape.

The goal here is not to be exhaustive, but rather to highlight exemplars of high-risk vulnerabilities. By dissecting these specific cases, organizations can gain a more concrete understanding of the types of threats that demand immediate prioritization and can use these examples to test their own detection and response capabilities. This targeted analysis serves as a practical supplement to the broader statistical picture painted earlier in the report.

The CVEs featured in this spotlight are selected through a rigorous methodology that balances both quantitative and qualitative risk factors. The primary criteria for inclusion encompass a high Common Vulnerability Scoring System (CVSS v3.1) base score, demonstrable evidence of exploitation in the wild (where such information is available), and technical characteristics that suggest widespread or systemic impact across Microsoft environments. Specific filtering rules guide the curation process: CVEs primarily rooted in the open-source Chromium project—often addressed by those upstream maintainers—are deliberately excluded to maintain focus on vulnerabilities inherent to Microsoft products, services, or unique integrations. An exception is made only if a Chromium-based CVE poses an unusually acute or distinct risk within the Microsoft ecosystem. In addition, the selection process identifies and consolidates functionally redundant CVEs; Microsoft may occasionally issue several vulnerability identifiers for essentially the same underlying flaw, distinguished only by minor technicalities or affected product sub-versions. Such duplicates are either merged for analysis or represented by a single, most relevant CVE to ensure the spotlight accurately reflects the breadth and nature of unique threat vectors observed during the quarter. This quarter, no “Worst Case” CVEs—defined as those with an even more extreme risk profile—were identified, underscoring the selectivity and focused nature of the spotlight list.

For each vulnerability included in this spotlight, the report details the CVE identifier, official CVSS v3.1 base score, exploitability attributes (such as required privileges and user interaction), affected platforms, and a concise assessment of potential organizational impact. To establish a quantitative baseline, Figure 13 visualizes the CVSS base scores for the ten spotlight CVEs. The scores span an exceptionally narrow band, from 9.8 to 9.9, placing every entry unequivocally in the Critical severity tier. Notably, nine CVEs are rated at 9.8, while only CVE-2025-21415 (Azure AI Face Service Elevation of Privilege) achieves the peak score of 9.9. This tight clustering at the highest severity level signals a uniformly acute risk profile among the spotlighted vulnerabilities, emphasizing that each represents a substantial potential vector for compromise or disruption.

To complement the detailed analysis of specific CVEs, we also explore broader patterns within the quarter's vulnerability landscape using a visualization technique called t-distributed Stochastic Neighbor Embedding (t-SNE). This method processes complex CVE data—encompassing attributes such as CVSS scores, attack vectors, privileges required, user interaction, and CVE categories (including distinctions like Microsoft Windows-based versus Chromium-based vulnerabilities)—by projecting these multi-faceted characteristics into a two-dimensional map. While t-SNE is not a conventional tool for daily system administration, its application here can help reveal inherent groupings or 'profiles' among diverse vulnerabilities. By observing how these CVEs cluster, we can potentially identify underlying similarities or distinctions in their nature that might otherwise be obscured in raw data, offering another perspective on threat trends.

Figure 14 presents this t-SNE projection for the quarter’s full range of CVEs, illustrating how various vulnerability types—particularly those based on Microsoft Windows and those originating from Chromium—form clearly distinct clusters according to their technical signatures. In compiling this visualization, the underlying dataset is de-duplicated by consolidating functionally identical Microsoft CVEs, so the resulting clusters reflect genuinely different vulnerability profiles rather than statistical artifacts of repeated reporting. The associated chart insight highlights a pronounced separation: elevation-of-privilege (EoP), local-vector vulnerabilities appear as a dense cluster on one side, while chromium-based, network-vector CVEs form a segregated group on the opposite side. This minimal intermingling between local privilege escalation and network-based attack vectors underscores fundamental technical and exploitative differences among the most severe vulnerabilities, reinforcing the significance of distinct risk management and detection approaches for each class.

The following entries will now delve into the specifics of the high-priority vulnerabilities identified through the selection process described above.

Spotlight CVEs Summary Details

CVE-2025-21415 - Azure AI Face Service Elevation of Privilege Vulnerability

None

CVE-2023-32002 - HackerOne: CVE-2023-32002 Node.js Module._load() policy Remote Code Execution Vulnerability

None

CVE-2024-43498 - .NET and Visual Studio Remote Code Execution Vulnerability

None

CVE-2025-1974 - Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller

None

CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability

CVE-2025-21298 is a critical remote code execution vulnerability affecting Microsoft Outlook due to a use after free flaw in the OLE component. An attacker can exploit this vulnerability by sending a specially crafted email that, when opened or previewed, allows the execution of arbitrary code on the victim's machine without requiring user interaction. The attack vector is network-based, making it remotely exploitable. The vulnerability has a CVSS score of 9.8, indicating a high severity level, with potential impacts on confidentiality, integrity, and availability. Microsoft has released an official fix for this vulnerability, and system administrators are advised to apply the security updates provided in the January 2025 rollup. To mitigate risks before applying the update, users should configure Microsoft Outlook to read emails in plain text format, which can be done by following these steps: 1. Open Outlook. 2. Go to File > Options > Trust Center > Trust Center Settings. 3. Select Email Security and check 'Read all standard mail in plain text'. This workaround will prevent the rendering of rich content that could exploit the vulnerability.

CVE-2025-21307 - Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

A critical remote code execution vulnerability exists in the Windows Reliable Multicast Transport Driver (RMCAST), identified as CVE-2025-21307. This vulnerability is caused by a use after free condition, allowing an unauthenticated attacker to send specially crafted packets to an open Pragmatic General Multicast (PGM) socket on the server. Exploitation does not require user interaction and can be executed remotely, making it highly dangerous. The potential impact includes total loss of confidentiality, integrity, and availability of the affected system. Microsoft has released an official fix for this vulnerability, and system administrators are strongly advised to apply the security updates available for their respective Windows versions. To mitigate the risk, it is recommended to ensure that no programs are actively listening on PGM ports and to protect access to any open ports at the network level using firewalls. Additionally, avoid exposing PGM receivers to the public internet. For further details, refer to the Microsoft Security Update Guide.

CVE-2025-21311 - Windows NTLM V1 Elevation of Privilege Vulnerability

CVE-2025-21311 is a critical elevation of privilege vulnerability affecting Windows NTLM V1. The vulnerability arises from an incorrect implementation of the authentication algorithm, allowing an attacker to exploit it remotely without requiring user interaction or prior access. The attack vector is network-based, and the complexity is low, making it easier for attackers to exploit. Successful exploitation could lead to a complete loss of confidentiality, integrity, and availability of the affected systems. Microsoft has released an official fix for this vulnerability, and system administrators are advised to apply the security updates provided for the following systems: 1. Windows Server 2025 - Build 10.0.26100.2894 2. Windows 11 Version 24H2 for x64-based Systems - Build 10.0.26100.2894 3. Windows 11 Version 24H2 for ARM64-based Systems - Build 10.0.26100.2894 4. Windows Server 2022, 23H2 Edition (Server Core installation) - Build 10.0.25398.1369 5. Windows Server 2025 (Server Core installation) - Build 10.0.26100.2894 Additionally, it is recommended to set the LmCompatabilityLvl to its maximum value (5) to prevent the use of the older NTLMv1 protocol while still allowing NTLMv2.

CVE-2025-21355 - Microsoft Bing Remote Code Execution Vulnerability

None

CVE-2025-21396 - Microsoft Account Elevation of Privilege Vulnerability

None

CVE-2025-24989 - Microsoft Power Pages Elevation of Privilege Vulnerability

None

High Risk CVEs
0
±0.0%

Weighted score (network + low complexity + low privileges + no interaction)

Loading chart...
Figure 13. CVSS scores of this quarter's most critical Windows and Edge CVEs.
Chart Insight

The CVSS base scores for the ten spotlight CVEs span a very narrow range of 9.8 to 9.9, placing all entries firmly in the Critical severity category. Nine of the CVEs share an identical score of 9.8, while CVE-2025-21415 (Azure AI Face Service Elevation of Privilege) alone reaches the top score of 9.9. This tight clustering at the highest severity level underscores the uniformly extreme risk profile of the quarter’s highlighted vulnerabilities.

Loading chart...
Figure 14. t-SNE projection of Windows and Edge CVEs showing distinct vulnerability profiles.
Chart Insight

The t-SNE visualization shows the EoP, Local-Vector CVEs (red markers) tightly clustered on the left side of the plot, while the chromium-based Network-Vector CVEs (purple markers) form a separate grouping on the right. There is minimal intermingling between the two profiles, indicating clear separation in the underlying feature space. No significant outliers bridge these two clusters, underscoring that the EoP and chromium-based network-attack vectors occupy distinct regions in the reduced-dimensional embedding.

Table 7.1. Details of Spotlighted Windows Critical Vulnerabilities.
CVE IDPublishedCVSS ScoreTitleCWE ID
CVE-2025-214152025-01-299.90
Azure AI Face Service Elevation of Privilege Vulnerability
CWE-290
CVE-2023-320022025-02-119.80
HackerOne: CVE-2023-32002 Node.js `Module._load()` policy Remote Code Execution Vulnerability
CWE-288
CVE-2024-434982025-01-299.80
.NET and Visual Studio Remote Code Execution Vulnerability
CWE-843
CVE-2025-19742025-03-249.80
Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
CWE-653
CVE-2025-212982025-01-149.80
Windows OLE Remote Code Execution Vulnerability
CWE-416
CVE-2025-213072025-01-149.80
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CWE-416
CVE-2025-213112025-01-149.80
Windows NTLM V1 Elevation of Privilege Vulnerability
CWE-303
CVE-2025-213552025-02-199.80
Microsoft Bing Remote Code Execution Vulnerability
CWE-306
CVE-2025-213962025-01-299.80
Microsoft Account Elevation of Privilege Vulnerability
CWE-862
CVE-2025-249892025-02-199.80
Microsoft Power Pages Elevation of Privilege Vulnerability
CWE-284

Summary

The analysis in this section has underscored the critical importance of focusing on the most severe vulnerabilities affecting Microsoft environments. By spotlighting high-risk CVEs—characterized by their elevated CVSS scores, low exploit complexity, and distinct attack vectors—this report highlights both remote code execution and local elevation of privilege vulnerabilities as pressing threats. The detailed breakdown emphasizes that while these individual cases provide a glimpse into the upper echelon of risk, they consistently echo broader trends in exploitation methods, necessitating immediate remediation and strategic tuning of detection and protection mechanisms.

This concentrated examination reinforces the need for tailored defensive measures that address both external network attacks and internal privilege escalations. Prioritizing rapid patch deployment and enhancing monitoring capabilities will be essential in mitigating these acute risks. As this focused review comes to a close, the insights gathered here set the stage for broader discussions on evolving trends and the adaptive security strategies required to maintain robust protection across Microsoft environments.

Conclusion

Conclusion

The key theme emerging from the PortalFuse Quarterly Security Report for Q1 2025 is the sustained prevalence and operational risk posed by high-severity vulnerabilities across Microsoft’s core platforms, particularly Windows and Edge. This quarter, approximately 70% of all tracked Common Vulnerabilities and Exposures (CVEs) were designated as Critical or Important, underscoring a persistently elevated risk environment. The high overall median CVSS score and the recurrent emergence of Remote Code Execution (RCE) as the top impact category reinforce the strategic imperative for ongoing vigilance and resource prioritization in threat management.

Throughout the report, multiple analytical sections converge on the finding that network-based, easily exploitable vulnerabilities comprise a significant portion of the Microsoft attack surface. The CVE landscape analysis documented not only a notable concentration of remote code execution and privilege escalation vulnerabilities but also the increasing impact of such weaknesses on modern platforms, particularly Windows 11. Correlatively, the attack surface evaluation highlighted that the vast majority of exploitable CVEs required minimal attacker effort to compromise network-connected assets, further amplifying the urgency for systematically reducing exposure to these high-leverage threat vectors.

The review of CVSS distributions and common weakness enumerations illuminated that, while the overall technical complexity of attacks remains moderate, the convergence of systemic weaknesses—especially those associated with remote exploitability—continues to accelerate remediation burdens. The timeliness assessment showed that response intervals for critical issues are improving, yet the continued high throughput of severe disclosures points to a challenging equilibrium between vulnerability management workload and actual mitigation capacity. The critical spotlight analysis further emphasized that, despite only a limited proportion being actively exploited (approximately 5%), the potential operational impact of these vulnerabilities remains disproportionately high for organizations with heavy Microsoft product dependencies.

Looking forward, the evidence presented in this report indicates that sustained emphasis on high-severity vulnerability trends, particularly those with proven low exploit complexity and broad impact, will remain essential for effective risk management. Continued observation of remediation timeliness, evolving attack vectors in Windows 11, and persistent patterns in RCE vulnerabilities will be central to future security posture assessments. The data further suggests that organizations should anticipate future quarters presenting similar challenges in terms of volume and severity, necessitating strategic investments in detection, response, and configuration management capabilities. This report concludes with a clear recognition of the ongoing demands placed on security teams and the need for adaptive, data-driven strategies to manage Microsoft-centric risk landscapes.

Appendix

Table A1. CVEs Included in This Report (Windows-Specific)

CVE IDTitleCVE CategorySeverityCVSS ScorePublished
CVE-2025-21351CVE-2025-21351 Windows Active Directory Domain Services API Denial of Service VulnerabilityDenial of Servicehigh7.52025-02-11
CVE-2025-21181CVE-2025-21181 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-02-11
CVE-2024-43499CVE-2024-43499 .NET and Visual Studio Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-29
CVE-2024-43485CVE-2024-43485 .NET and Visual Studio Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-29
CVE-2025-21218CVE-2025-21218 Windows Kerberos Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21270CVE-2025-21270 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21251CVE-2025-21251 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21389CVE-2025-21389 Windows upnphost.dll Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21231CVE-2025-21231 IP Helper Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21230CVE-2025-21230 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21207CVE-2025-21207 Windows Connected Devices Platform Service (Cdpsvc) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21330CVE-2025-21330 Windows Remote Desktop Services Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21300CVE-2025-21300 Windows upnphost.dll Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21290CVE-2025-21290 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21289CVE-2025-21289 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21285CVE-2025-21285 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21277CVE-2025-21277 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2025-21276CVE-2025-21276 Windows MapUrlToZone Denial of Service VulnerabilityDenial of Servicehigh7.52025-01-14
CVE-2021-45985CVE-2021-45985 Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-readDenial of Servicehigh7.52025-01-14
CVE-2025-21352CVE-2025-21352 Internet Connection Sharing (ICS) Denial of Service VulnerabilityDenial of Servicemedium6.52025-02-11
CVE-2025-21254CVE-2025-21254 Internet Connection Sharing (ICS) Denial of Service VulnerabilityDenial of Servicemedium6.52025-02-11
CVE-2025-21216CVE-2025-21216 Internet Connection Sharing (ICS) Denial of Service VulnerabilityDenial of Servicemedium6.52025-02-11
CVE-2025-21212CVE-2025-21212 Internet Connection Sharing (ICS) Denial of Service VulnerabilityDenial of Servicemedium6.52025-02-11
CVE-2025-21313CVE-2025-21313 Windows Security Account Manager (SAM) Denial of Service VulnerabilityDenial of Servicemedium6.52025-01-14
CVE-2025-21278CVE-2025-21278 Windows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityDenial of Servicemedium6.22025-01-14
CVE-2025-21347CVE-2025-21347 Windows Deployment Services Denial of Service VulnerabilityDenial of Servicemedium6.02025-02-11
CVE-2025-21350CVE-2025-21350 Windows Kerberos Denial of Service VulnerabilityDenial of Servicemedium5.92025-02-11
CVE-2025-21225CVE-2025-21225 Windows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityDenial of Servicemedium5.92025-01-14
CVE-2025-21284CVE-2025-21284 Windows Virtual Trusted Platform Module Denial of Service VulnerabilityDenial of Servicemedium5.52025-01-14
CVE-2025-21280CVE-2025-21280 Windows Virtual Trusted Platform Module Denial of Service VulnerabilityDenial of Servicemedium5.52025-01-14
CVE-2025-21274CVE-2025-21274 Windows Event Tracing Denial of Service VulnerabilityDenial of Servicemedium5.52025-01-14
CVE-2025-24513CVE-2025-24513 Kubernetes: Vulnerability in Kubernetes NGINX Ingress ControllerDenial of Servicemedium4.82025-03-24
CVE-2025-21179CVE-2025-21179 DHCP Client Service Denial of Service VulnerabilityDenial of Servicemedium4.82025-02-11
CVE-2025-24997CVE-2025-24997 DirectX Graphics Kernel File Denial of Service VulnerabilityDenial of Servicemedium4.42025-03-11
CVE-2025-24997DirectX Graphics Kernel File Denial of Service VulnerabilityDenial of Servicemedium4.42025-03-11
CVE-2025-21385CVE-2025-21385 Microsoft Purview Information Disclosure VulnerabilityInformation Disclosurehigh8.82025-01-09
CVE-2025-21380CVE-2025-21380 Azure Marketplace SaaS Resources Information Disclosure VulnerabilityInformation Disclosurehigh8.82025-01-09
CVE-2025-21383CVE-2025-21383 Microsoft Excel Information Disclosure VulnerabilityInformation Disclosurehigh7.82025-02-11
CVE-2025-21343CVE-2025-21343 Windows Web Threat Defense User Service Information Disclosure VulnerabilityInformation Disclosurehigh7.52025-01-14
CVE-2025-21220CVE-2025-21220 Microsoft Message Queuing Information Disclosure VulnerabilityInformation Disclosurehigh7.52025-01-14
CVE-2024-50338CVE-2024-50338 GitHub: CVE-2024-50338 Malformed URL allows information disclosure through git-credential-managerInformation Disclosurehigh7.42025-01-14
CVE-2025-0441Chromium: CVE-2025-0441 Inappropriate implementation in Fenced FramesInformation Disclosuremedium6.52025-01-16
CVE-2025-21301CVE-2025-21301 Windows Geolocation Service Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-01-14
CVE-2025-21288CVE-2025-21288 Windows COM Server Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-01-14
CVE-2025-21272CVE-2025-21272 Windows COM Server Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-01-14
CVE-2025-21403CVE-2025-21403 On-Premises Data Gateway Information Disclosure VulnerabilityInformation Disclosuremedium6.42025-01-14
CVE-2025-21242CVE-2025-21242 Windows Kerberos Information Disclosure VulnerabilityInformation Disclosuremedium5.92025-01-14
CVE-2025-21336CVE-2025-21336 Windows Cryptographic Information Disclosure VulnerabilityInformation Disclosuremedium5.62025-01-14
CVE-2025-24992CVE-2025-24992 Windows NTFS Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-03-11
CVE-2025-24991CVE-2025-24991 Windows NTFS Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-03-11
CVE-2025-21317CVE-2025-21317 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21257CVE-2025-21257 Windows WLAN AutoConfig Service Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21374CVE-2025-21374 Windows CSC Service Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21323CVE-2025-21323 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21321CVE-2025-21321 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21320CVE-2025-21320 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21319CVE-2025-21319 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21318CVE-2025-21318 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-21316CVE-2025-21316 Windows Kernel Memory Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-01-14
CVE-2025-24984CVE-2025-24984 Windows NTFS Information Disclosure VulnerabilityInformation Disclosuremedium4.62025-03-11
CVE-2025-21215CVE-2025-21215 Secure Boot Security Feature Bypass VulnerabilityInformation Disclosuremedium4.62025-01-14
CVE-2025-24055CVE-2025-24055 Windows USB Video Class System Driver Information Disclosure VulnerabilityInformation Disclosuremedium4.32025-03-11
CVE-2025-24055Windows USB Video Class System Driver Information Disclosure VulnerabilityInformation Disclosuremedium4.32025-03-11
CVE-2025-21214CVE-2025-21214 Windows BitLocker Information Disclosure VulnerabilityInformation Disclosuremedium4.22025-01-14
CVE-2025-21210CVE-2025-21210 Windows BitLocker Information Disclosure VulnerabilityInformation Disclosuremedium4.22025-01-14
CVE-2025-21312CVE-2025-21312 Windows Smart Card Reader Information Disclosure VulnerabilityInformation Disclosurelow2.42025-01-14
CVE-2025-21311CVE-2025-21311 Windows NTLM V1 Elevation of Privilege VulnerabilityPrivilege Elevationcritical9.82025-01-14
CVE-2025-24989CVE-2025-24989 Microsoft Power Pages Elevation of Privilege VulnerabilityPrivilege Elevationhigh9.82025-02-21
CVE-2025-24989CVE-2025-24989 Microsoft Power Pages Elevation of Privilege VulnerabilityPrivilege Elevationhigh9.82025-02-19
CVE-2025-21396CVE-2025-21396 Microsoft Account Elevation of Privilege VulnerabilityPrivilege Elevationhigh9.82025-02-06
CVE-2025-21396CVE-2025-21396 Microsoft Account Elevation of Privilege VulnerabilityPrivilege Elevationhigh9.82025-01-29
CVE-2025-21177CVE-2025-21177 Microsoft Dynamics 365 Sales Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.82025-02-06
CVE-2025-0443Chromium: CVE-2025-0443 Insufficient data validation in ExtensionsPrivilege Elevationhigh8.82025-01-16
CVE-2025-0447Chromium: CVE-2025-0447 Inappropriate implementation in NavigationPrivilege Elevationhigh8.82025-01-16
CVE-2025-21370CVE-2025-21370 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.82025-01-14
CVE-2025-21293CVE-2025-21293 Active Directory Domain Services Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.82025-01-14
CVE-2025-21292CVE-2025-21292 Windows Search Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.82025-01-14
CVE-2025-24049CVE-2025-24049 Azure Command Line Integration (CLI) Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.42025-03-11
CVE-2025-26683CVE-2025-26683 Azure Playwright Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.12025-03-31
CVE-2025-24995CVE-2025-24995 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24072CVE-2025-24072 Microsoft Local Security Authority (LSA) Server Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24067CVE-2025-24067 Kernel Streaming Service Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24066CVE-2025-24066 Kernel Streaming Service Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24059CVE-2025-24059 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24050CVE-2025-24050 Windows Hyper-V Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24048CVE-2025-24048 Windows Hyper-V Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24046CVE-2025-24046 Kernel Streaming Service Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-24044CVE-2025-24044 Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2024-9157CVE-2024-9157 Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading VulnerabilityPrivilege Elevationhigh7.82025-03-11
CVE-2025-21325CVE-2025-21325 Windows Secure Kernel Mode Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-21
CVE-2025-21322CVE-2025-21322 Microsoft PC Manager Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21375CVE-2025-21375 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21373CVE-2025-21373 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21367CVE-2025-21367 Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21358CVE-2025-21358 Windows Core Messaging Elevation of Privileges VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21420CVE-2025-21420 Windows Disk Cleanup Tool Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21418CVE-2025-21418 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-02-11
CVE-2025-21360CVE-2025-21360 Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-30
CVE-2025-21325Windows Secure Kernel Mode Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-16
CVE-2025-21271CVE-2025-21271 Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21235CVE-2025-21235 Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21234CVE-2025-21234 Windows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21372CVE-2025-21372 Microsoft Brokering File System Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21360CVE-2025-21360 Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21335CVE-2025-21335 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21334CVE-2025-21334 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21333CVE-2025-21333 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21315CVE-2025-21315 Microsoft Brokering File System Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21304CVE-2025-21304 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21275CVE-2025-21275 Windows App Package Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21382CVE-2025-21382 Windows Graphics Component Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21378CVE-2025-21378 Windows CSC Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21287CVE-2025-21287 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21281CVE-2025-21281 Microsoft COM for Windows Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21335Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21334Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-21333Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-01-14
CVE-2025-26634CVE-2025-26634 Windows Core Messaging Elevation of Privileges VulnerabilityPrivilege Elevationhigh7.52025-03-11
CVE-2025-21183CVE-2025-21183 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.42025-02-11
CVE-2025-21182CVE-2025-21182 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.42025-02-11
CVE-2025-25003CVE-2025-25003 Visual Studio Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-03-11
CVE-2025-24998CVE-2025-24998 Visual Studio Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-03-11
CVE-2025-24994CVE-2025-24994 Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-03-11
CVE-2025-24076CVE-2025-24076 Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-03-11
CVE-2025-26631CVE-2025-26631 Visual Studio Code Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-03-11
CVE-2022-30170CVE-2022-30170 Windows Credential Roaming Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-03-11
CVE-2025-24042CVE-2025-24042 Visual Studio Code JS Debug Extension Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-02-11
CVE-2025-24039CVE-2025-24039 Visual Studio Code Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-02-11
CVE-2025-21206CVE-2025-21206 Visual Studio Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-02-11
CVE-2025-21173CVE-2025-21173 .NET Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-01-14
CVE-2025-21405CVE-2025-21405 Visual Studio Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-01-14
CVE-2025-21331CVE-2025-21331 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-01-14
CVE-2024-43594CVE-2024-43594 Microsoft System Center Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-01-07
CVE-2025-24053CVE-2025-24053 Microsoft Dataverse Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.22025-03-13
CVE-2025-25008CVE-2025-25008 Windows Server Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.12025-03-23
CVE-2025-25008CVE-2025-25008 Windows Server Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.12025-03-11
CVE-2025-21391CVE-2025-21391 Windows Storage Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.12025-02-11
CVE-2025-21419CVE-2025-21419 Windows Setup Files Cleanup Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.12025-02-11
CVE-2025-26627CVE-2025-26627 Azure Arc Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-03-11
CVE-2025-24983CVE-2025-24983 Windows Win32 Kernel Subsystem Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-03-11
CVE-2025-24070CVE-2025-24070 ASP.NET Core and Visual Studio Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-03-11
CVE-2025-24036CVE-2025-24036 Microsoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-02-11
CVE-2025-21184CVE-2025-21184 Windows Core Messaging Elevation of Privileges VulnerabilityPrivilege Elevationhigh7.02025-02-11
CVE-2025-21414CVE-2025-21414 Windows Core Messaging Elevation of Privileges VulnerabilityPrivilege Elevationhigh7.02025-02-11
CVE-2025-21199CVE-2025-21199 Azure Agent Installer for Backup and Site Recovery Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.72025-03-11
CVE-2025-24988CVE-2025-24988 Windows USB Video Class System Driver Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-03-11
CVE-2025-24987CVE-2025-24987 Windows USB Video Class System Driver Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-03-11
CVE-2024-49109CVE-2024-49109 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-21
CVE-2025-21265CVE-2025-21265 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21263CVE-2025-21263 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21261CVE-2025-21261 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21260CVE-2025-21260 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21258CVE-2025-21258 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21256CVE-2025-21256 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21255CVE-2025-21255 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21249CVE-2025-21249 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21232CVE-2025-21232 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21229CVE-2025-21229 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21228CVE-2025-21228 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21227CVE-2025-21227 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21226CVE-2025-21226 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21341CVE-2025-21341 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21327CVE-2025-21327 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21324CVE-2025-21324 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21310CVE-2025-21310 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.62025-01-14
CVE-2025-21185Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.52025-01-16
CVE-2025-21202CVE-2025-21202 Windows Recovery Environment Agent Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.12025-01-14
CVE-2025-21188CVE-2025-21188 Azure Network Watcher VM Extension Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.02025-02-11
CVE-2025-21337CVE-2025-21337 Windows NTFS Elevation of Privilege VulnerabilityPrivilege Elevationlow3.32025-02-11
CVE-2025-1974CVE-2025-1974 Kubernetes: Vulnerability in Kubernetes NGINX Ingress ControllerRemote Code Executioncritical9.82025-03-24
CVE-2023-32002CVE-2023-32002 HackerOne: CVE-2023-32002 Node.js `Module._load()` policy Remote Code Execution VulnerabilityRemote Code Executioncritical9.82025-02-11
CVE-2024-43498CVE-2024-43498 .NET and Visual Studio Remote Code Execution VulnerabilityRemote Code Executioncritical9.82025-01-29
CVE-2025-21307CVE-2025-21307 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityRemote Code Executioncritical9.82025-01-14
CVE-2025-21298CVE-2025-21298 Windows OLE Remote Code Execution VulnerabilityRemote Code Executioncritical9.82025-01-14
CVE-2025-21298Windows OLE Remote Code Execution VulnerabilityRemote Code Executioncritical9.82025-01-14
CVE-2025-21198CVE-2025-21198 Microsoft High Performance Compute (HPC) Pack Remote Code Execution VulnerabilityRemote Code Executioncritical9.02025-02-11
CVE-2025-21355CVE-2025-21355 Microsoft Bing Remote Code Execution VulnerabilityRemote Code Executionhigh9.82025-02-19
CVE-2025-1098CVE-2025-1098 Kubernetes: Vulnerability in Kubernetes NGINX Ingress ControllerRemote Code Executionhigh8.82025-03-24
CVE-2025-1097CVE-2025-1097 Kubernetes: Vulnerability in Kubernetes NGINX Ingress ControllerRemote Code Executionhigh8.82025-03-24
CVE-2025-24514CVE-2025-24514 Kubernetes: Vulnerability in Kubernetes NGINX Ingress ControllerRemote Code Executionhigh8.82025-03-24
CVE-2025-26645CVE-2025-26645 Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-03-23
CVE-2025-26645CVE-2025-26645 Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-03-11
CVE-2025-24056CVE-2025-24056 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-03-11
CVE-2025-24051CVE-2025-24051 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-03-11
CVE-2025-26645Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-03-11
CVE-2025-21178CVE-2025-21178 Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-14
CVE-2025-21178CVE-2025-21178 Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21410CVE-2025-21410 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21407CVE-2025-21407 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21406CVE-2025-21406 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21371CVE-2025-21371 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21369CVE-2025-21369 Microsoft Digest Authentication Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21368CVE-2025-21368 Microsoft Digest Authentication Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21208CVE-2025-21208 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21201CVE-2025-21201 Windows Telephony Server Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21200CVE-2025-21200 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21190CVE-2025-21190 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21176CVE-2025-21176 .NET, .NET Framework, and Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-11
CVE-2025-21408CVE-2025-21408 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-06
CVE-2025-21342CVE-2025-21342 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-02-06
CVE-2025-21237CVE-2025-21237 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-29
CVE-2025-21178CVE-2025-21178 Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21291CVE-2025-21291 Windows Direct Show Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21266CVE-2025-21266 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21252CVE-2025-21252 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21250CVE-2025-21250 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21248CVE-2025-21248 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21246CVE-2025-21246 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21245CVE-2025-21245 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21244CVE-2025-21244 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21243CVE-2025-21243 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21241CVE-2025-21241 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21240CVE-2025-21240 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21239CVE-2025-21239 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21238CVE-2025-21238 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21237CVE-2025-21237 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21236CVE-2025-21236 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21233CVE-2025-21233 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21223CVE-2025-21223 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21176CVE-2025-21176 .NET, .NET Framework, and Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21417CVE-2025-21417 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21339CVE-2025-21339 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21413CVE-2025-21413 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21411CVE-2025-21411 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21409CVE-2025-21409 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21306CVE-2025-21306 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21305CVE-2025-21305 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21303CVE-2025-21303 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21302CVE-2025-21302 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21286CVE-2025-21286 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21282CVE-2025-21282 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21273CVE-2025-21273 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-21237Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-01-14
CVE-2025-24084CVE-2025-24084 Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution VulnerabilityRemote Code Executionhigh8.42025-03-11
CVE-2025-24084Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution VulnerabilityRemote Code Executionhigh8.42025-03-11
CVE-2025-21362CVE-2025-21362 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh8.42025-01-14
CVE-2025-21354CVE-2025-21354 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh8.42025-01-14
CVE-2025-21362CVE-2025-21362 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh8.42025-01-14
CVE-2025-21354CVE-2025-21354 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh8.42025-01-14
CVE-2024-49119CVE-2024-49119 Windows Remote Desktop Services Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-03-19
CVE-2025-24045CVE-2025-24045 Windows Remote Desktop Services Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-03-11
CVE-2024-49116CVE-2024-49116 Windows Remote Desktop Services Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-03-11
CVE-2025-24064CVE-2025-24064 Windows Domain Name Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-03-11
CVE-2025-24035CVE-2025-24035 Windows Remote Desktop Services Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-03-11
CVE-2025-21376CVE-2025-21376 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-02-11
CVE-2025-21224CVE-2025-21224 Windows Line Printer Daemon (LPD) Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-01-14
CVE-2025-21309CVE-2025-21309 Windows Remote Desktop Services Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-01-14
CVE-2025-21297CVE-2025-21297 Windows Remote Desktop Services Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-01-14
CVE-2025-21295CVE-2025-21295 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-01-14
CVE-2025-21294CVE-2025-21294 Microsoft Digest Authentication Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-01-14
CVE-2025-21400CVE-2025-21400 Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Executionhigh8.02025-02-11
CVE-2025-24083CVE-2025-24083 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24082CVE-2025-24082 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24081CVE-2025-24081 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24080CVE-2025-24080 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24079CVE-2025-24079 Microsoft Word Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24077CVE-2025-24077 Microsoft Word Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24075CVE-2025-24075 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24057CVE-2025-24057 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-26630CVE-2025-26630 Microsoft Access Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-26629CVE-2025-26629 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24993CVE-2025-24993 Windows NTFS Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-24985CVE-2025-24985 Windows Fast FAT File System Driver Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-21180CVE-2025-21180 Windows exFAT File System Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-03-11
CVE-2025-21397CVE-2025-21397 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21394CVE-2025-21394 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21392CVE-2025-21392 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21390CVE-2025-21390 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21387CVE-2025-21387 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21386CVE-2025-21386 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21381CVE-2025-21381 Microsoft Excel Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-02-11
CVE-2025-21395CVE-2025-21395 Microsoft Access Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21187CVE-2025-21187 Microsoft Power Automate Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21186CVE-2025-21186 Microsoft Access Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21366CVE-2025-21366 Microsoft Access Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21365CVE-2025-21365 Microsoft Office Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21363CVE-2025-21363 Microsoft Word Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21361CVE-2025-21361 Microsoft Outlook Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21356CVE-2025-21356 Microsoft Office Visio Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21345CVE-2025-21345 Microsoft Office Visio Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21344CVE-2025-21344 Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21326CVE-2025-21326 Internet Explorer Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21402CVE-2025-21402 Microsoft Office OneNote Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21338CVE-2025-21338 GDI+ Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21338GDI+ Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-21338GDI+ Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-01-14
CVE-2025-24043CVE-2025-24043 WinDbg Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-03-11
CVE-2025-21172CVE-2025-21172 .NET and Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-02-11
CVE-2025-21171CVE-2025-21171 .NET Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-01-29
CVE-2025-21172CVE-2025-21172 .NET and Visual Studio Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-01-14
CVE-2025-21171CVE-2025-21171 .NET Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-01-14
CVE-2025-21296CVE-2025-21296 BranchCache Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-01-14
CVE-2025-21348CVE-2025-21348 Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Executionhigh7.22025-01-14
CVE-2025-21379CVE-2025-21379 DHCP Client Service Remote Code Execution VulnerabilityRemote Code Executionhigh7.12025-02-11
CVE-2025-24078CVE-2025-24078 Microsoft Word Remote Code Execution VulnerabilityRemote Code Executionhigh7.02025-03-11
CVE-2025-21283CVE-2025-21283 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionmedium8.82025-02-06
CVE-2025-21279CVE-2025-21279 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionmedium8.82025-02-06
CVE-2025-21357CVE-2025-21357 Microsoft Outlook Remote Code Execution VulnerabilityRemote Code Executionmedium6.72025-01-14
CVE-2025-29806CVE-2025-29806 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionmedium6.52025-03-21
CVE-2025-24986CVE-2025-24986 Azure Promptflow Remote Code Execution VulnerabilityRemote Code Executionmedium6.52025-03-11
CVE-2024-7344CVE-2024-7344 Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot BypassSecurity Feature Bypasshigh8.22025-01-29
CVE-2024-7344CVE-2024-7344 Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot BypassSecurity Feature Bypasshigh8.22025-01-14
CVE-2025-24061CVE-2025-24061 Windows Mark of the Web Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-03-11
CVE-2025-21359CVE-2025-21359 Windows Kernel Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-02-14
CVE-2025-21359CVE-2025-21359 Windows Kernel Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-02-11
CVE-2025-21359Windows Kernel Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-02-11
CVE-2025-21364CVE-2025-21364 Microsoft Excel Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-01-14
CVE-2025-21346CVE-2025-21346 Microsoft Office Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-01-14
CVE-2025-21299CVE-2025-21299 Windows Kerberos Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.82025-01-14
CVE-2024-30098CVE-2024-30098 Windows Cryptographic Services Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.52025-03-11
CVE-2025-21194CVE-2025-21194 Microsoft Surface Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.12025-02-11
CVE-2025-26633CVE-2025-26633 Microsoft Management Console Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.02025-03-11
CVE-2025-21332CVE-2025-21332 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium8.82025-01-14
CVE-2025-21211CVE-2025-21211 Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.82025-01-14
CVE-2023-24932CVE-2023-24932 Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.72025-02-11
CVE-2025-21340CVE-2025-21340 Windows Virtualization-Based Security (VBS) Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium5.52025-01-14
CVE-2025-21215CVE-2025-21215 Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.62025-01-29
CVE-2025-21213CVE-2025-21213 Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.62025-01-14
CVE-2025-21215Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.62025-01-14
CVE-2025-21401CVE-2025-21401 Microsoft Edge (Chromium-based) Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.52025-02-21
CVE-2025-21401Microsoft Edge (Chromium-based) Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.52025-02-13
CVE-2025-21401Microsoft Edge (Chromium-based) Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.52025-02-13
CVE-2025-21247CVE-2025-21247 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-03-11
CVE-2025-21269CVE-2025-21269 Windows HTML Platforms Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-01-14
CVE-2025-21268CVE-2025-21268 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-01-14
CVE-2025-21219CVE-2025-21219 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-01-14
CVE-2025-21189CVE-2025-21189 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-01-14
CVE-2025-21329CVE-2025-21329 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-01-14
CVE-2025-21328CVE-2025-21328 MapUrlToZone Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium4.32025-01-14
CVE-2025-21415CVE-2025-21415 Azure AI Face Service Elevation of Privilege VulnerabilitySpoofingcritical9.92025-01-29
CVE-2025-24996CVE-2025-24996 NTLM Hash Disclosure Spoofing VulnerabilitySpoofingmedium6.52025-03-11
CVE-2025-24071CVE-2025-24071 Microsoft Windows File Explorer Spoofing VulnerabilitySpoofingmedium6.52025-03-11
CVE-2025-24054CVE-2025-24054 NTLM Hash Disclosure Spoofing VulnerabilitySpoofingmedium6.52025-03-11
CVE-2025-24054NTLM Hash Disclosure Spoofing VulnerabilitySpoofingmedium6.52025-03-11
CVE-2025-21377CVE-2025-21377 NTLM Hash Disclosure Spoofing VulnerabilitySpoofingmedium6.52025-02-11
CVE-2025-0442Chromium: CVE-2025-0442 Inappropriate implementation in PaymentsSpoofingmedium6.52025-01-16
CVE-2025-0440Chromium: CVE-2025-0440 Inappropriate implementation in FullscreenSpoofingmedium6.52025-01-16
CVE-2025-0439Chromium: CVE-2025-0439 Race in FramesSpoofingmedium6.52025-01-16
CVE-2025-0435Chromium: CVE-2025-0435 Inappropriate implementation in NavigationSpoofingmedium6.52025-01-16
CVE-2025-21193CVE-2025-21193 Active Directory Federation Server Spoofing VulnerabilitySpoofingmedium6.52025-01-14
CVE-2025-21217CVE-2025-21217 Windows NTLM Spoofing VulnerabilitySpoofingmedium6.52025-01-14
CVE-2025-21314CVE-2025-21314 Windows SmartScreen Spoofing VulnerabilitySpoofingmedium6.52025-01-14
CVE-2025-21308CVE-2025-21308 Windows Themes Spoofing VulnerabilitySpoofingmedium6.52025-01-14
CVE-2025-0451Chromium: CVE-2025-0451 Inappropriate implementation in Extensions APISpoofingmedium6.32025-02-06
CVE-2025-21393CVE-2025-21393 Microsoft SharePoint Server Spoofing VulnerabilitySpoofingmedium6.32025-01-14
CVE-2025-26643CVE-2025-26643 Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofingmedium5.42025-03-07
CVE-2025-21262CVE-2025-21262 Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofingmedium5.42025-01-24
CVE-2025-21259CVE-2025-21259 Microsoft Outlook Spoofing VulnerabilitySpoofingmedium5.32025-02-11
CVE-2025-21253CVE-2025-21253 Microsoft Edge for IOS and Android Spoofing VulnerabilitySpoofingmedium5.32025-02-06
CVE-2025-21267CVE-2025-21267 Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofingmedium4.42025-02-06
CVE-2025-1923Chromium: CVE-2025-1923 Inappropriate Implementation in Permission PromptsSpoofingmedium4.32025-03-07
CVE-2025-1922Chromium: CVE-2025-1922 Inappropriate Implementation in SelectionSpoofingmedium4.32025-03-07
CVE-2025-1917Chromium: CVE-2025-1917 Inappropriate Implementation in Browser UISpoofingmedium4.32025-03-07
CVE-2025-21404CVE-2025-21404 Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofingmedium4.32025-02-06
CVE-2025-0448Chromium: CVE-2025-0448 Inappropriate implementation in CompositingSpoofingmedium4.32025-01-16
CVE-2025-0446Chromium: CVE-2025-0446 Inappropriate implementation in ExtensionsSpoofingmedium4.32025-01-16
CVE-2025-21349CVE-2025-21349 Windows Remote Desktop Configuration Service Tampering VulnerabilityTamperingmedium6.82025-02-11
CVE-2024-7344Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot BypassUnknownhigh8.22025-01-14
ADV990001ADV990001 Latest Servicing Stack UpdatesUnknownN/AN/A2025-03-11
ADV990001ADV990001 Latest Servicing Stack UpdatesUnknownN/AN/A2025-02-11
ADV990001ADV990001 Latest Servicing Stack UpdatesUnknownN/AN/A2025-01-14
CVE-2025-2476Chromium: CVE-2025-2476 Use after free in Lenschromium-basedhigh8.82025-03-21
CVE-2025-24201Chromium: CVE-2025-24201 Out of bounds write in GPU on Macchromium-basedhigh8.82025-03-12
CVE-2025-2137Chromium: CVE-2025-2137 Out of bounds read in V8chromium-basedhigh8.82025-03-12
CVE-2025-2136Chromium: CVE-2025-2136 Use after free in Inspectorchromium-basedhigh8.82025-03-12
CVE-2025-2135Chromium: CVE-2025-2135 Type Confusion in V8chromium-basedhigh8.82025-03-12
CVE-2025-1920Chromium: CVE-2025-1920 Type Confusion in V8chromium-basedhigh8.82025-03-12
CVE-2025-1919Chromium: CVE-2025-1919 Out of bounds read in Mediachromium-basedhigh8.82025-03-07
CVE-2025-1918Chromium: CVE-2025-1918 Out of bounds read in PDFiumchromium-basedhigh8.82025-03-07
CVE-2025-1916Chromium: CVE-2025-1916 Use after free in Profileschromium-basedhigh8.82025-03-07
CVE-2025-1914Chromium: CVE-2025-1914 Out of bounds read in V8chromium-basedhigh8.82025-03-07
CVE-2025-0999Chromium: CVE-2025-0999 Heap buffer overflow in V8chromium-basedhigh8.82025-02-21
CVE-2025-1426Chromium: CVE-2025-1006 Use after free in Networkchromium-basedhigh8.82025-02-21
CVE-2025-1006Chromium: CVE-2025-1426 Heap buffer overflow in GPUchromium-basedhigh8.82025-02-21
CVE-2025-0995 Chromium: CVE -2025-0995 Use after free in V8 chromium-basedhigh8.82025-02-14
CVE-2025-0762Chromium: CVE-2025-0762 Use after free in DevToolschromium-basedhigh8.82025-01-30
CVE-2025-0438Chromium: CVE-2025-0438 Stack buffer overflow in Tracingchromium-basedhigh8.82025-01-16
CVE-2025-0437Chromium: CVE-2025-0437 Out of bounds read in Metricschromium-basedhigh8.82025-01-16
CVE-2025-0436Chromium: CVE-2025-0436 Integer overflow in Skiachromium-basedhigh8.82025-01-16
CVE-2025-0434Chromium: CVE-2025-0434 Out of bounds memory access in V8chromium-basedhigh8.82025-01-16
CVE-2025-0291Chromium: CVE-2025-0291 Type Confusion in V8chromium-basedhigh8.82025-01-14
CVE-2025-2783Chromium: CVE-2025-2783 Incorrect handle provided in unspecified circumstances in Mojo on Windowschromium-basedhigh8.32025-03-26
CVE-2025-0611Chromium: CVE-2025-0612 Out of bounds memory access in V8chromium-basedhigh8.22025-01-27
CVE-2025-1915Chromium: CVE-2025-1915 Improper Limitation of a Pathname to a Restricted Directory in DevToolschromium-basedhigh8.12025-03-07
CVE-2025-0997 Chromium: CVE -2025-0997 Use after free in Navigation chromium-basedhigh8.12025-02-14
CVE-2025-29795CVE-2025-29795 Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerabilitychromium-basedhigh7.82025-03-21
CVE-2025-0612Chromium: CVE-2025-0611 Object corruption in V8chromium-basedhigh7.52025-01-27
CVE-2025-1921Chromium: CVE-2025-1921 Inappropriate Implementation in Media Streamchromium-basedmedium6.52025-03-07
CVE-2025-0444Chromium: CVE-2025-0444 Use after free in Skiachromium-basedmedium6.32025-02-06
CVE-2025-0996 Chromium: CVE -2025-0996 Inappropriate implementation in Browser UI chromium-basedmedium5.42025-02-14
CVE-2025-0445Chromium: CVE-2025-0445 Use after free in V8chromium-basedmedium5.42025-02-06
CVE-2025-0998 Chromium: CVE -2025-0998 Out of bounds memory access in V8 chromium-basedN/AN/A2025-02-14

Table A2. CVEs with CVSS scores that are outliers compared to their vulnerability category.

Outlier TypeCVSS ScoreCVE IDTitleCVE CategorySeverityPublished
High Outlier8.8CVE-2025-21385CVE-2025-21385 Microsoft Purview Information Disclosure VulnerabilityInformation Disclosurehigh2025-01-09
High Outlier8.8CVE-2025-21380CVE-2025-21380 Azure Marketplace SaaS Resources Information Disclosure VulnerabilityInformation Disclosurehigh2025-01-09
Low Outlier2.4CVE-2025-21312CVE-2025-21312 Windows Smart Card Reader Information Disclosure VulnerabilityInformation Disclosurelow2025-01-14
High Outlier9.8CVE-2025-21311CVE-2025-21311 Windows NTLM V1 Elevation of Privilege VulnerabilityPrivilege Elevationcritical2025-01-14
High Outlier9.8CVE-2025-24989CVE-2025-24989 Microsoft Power Pages Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-02-21
High Outlier9.8CVE-2025-24989CVE-2025-24989 Microsoft Power Pages Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-02-19
High Outlier9.8CVE-2025-21396CVE-2025-21396 Microsoft Account Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-02-06
High Outlier9.8CVE-2025-21396CVE-2025-21396 Microsoft Account Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-01-29
Low Outlier3.3CVE-2025-21337CVE-2025-21337 Windows NTFS Elevation of Privilege VulnerabilityPrivilege Elevationlow2025-02-11
High Outlier9.9CVE-2025-21415CVE-2025-21415 Azure AI Face Service Elevation of Privilege VulnerabilitySpoofingcritical2025-01-29
Low Outlier6.5CVE-2025-1921Chromium: CVE-2025-1921 Inappropriate Implementation in Media Streamchromium-basedmedium2025-03-07
Low Outlier6.3CVE-2025-0444Chromium: CVE-2025-0444 Use after free in Skiachromium-basedmedium2025-02-06
Low Outlier5.4CVE-2025-0996 Chromium: CVE -2025-0996 Inappropriate implementation in Browser UI chromium-basedmedium2025-02-14
Low Outlier5.4CVE-2025-0445Chromium: CVE-2025-0445 Use after free in V8chromium-basedmedium2025-02-06

Table A3. All Calculated Metrics

#Metric NameValue
1Total CVEs392
2Critical Count9
3High Count260
4Medium Count117
5Low Count2
6% Critical & High CVEs68.62
7High-to-Total Ratio66.33
8Most Volatile Month2025-01
9Median CVSS7.8
10P90 CVSS8.8
11Highest CVSS9.9
12Lowest CVSS2.4
13CVSS IQR2.2
14CVSS Score Variability1.37
15Average CVSS Score7.42
16CVSS Range by Category: Chromium-Based
  • Q1: 8.12
  • Median: 8.8
  • Q3: 8.8
  • IQR: 0.68
  • Lower_Fence: 7.11
  • Upper_Fence: 9.81
  • Count: 30
  • Mean: 8.25
  • StdDev: 1.02
17CVSS Range by Category: Denial Of Service
  • Q1: 5.95
  • Median: 7.5
  • Q3: 7.5
  • IQR: 1.55
  • Lower_Fence: 3.63
  • Upper_Fence: 9.82
  • Count: 35
  • Mean: 6.68
  • StdDev: 1.04
18CVSS Range by Category: Disclosure
  • Q1: 5.5
  • Median: 5.5
  • Q3: 6.5
  • IQR: 1.0
  • Lower_Fence: 4.0
  • Upper_Fence: 8.0
  • Count: 31
  • Mean: 5.83
  • StdDev: 1.39
19CVSS Range by Category: Feature Bypass
  • Q1: 4.5
  • Median: 6.7
  • Q3: 7.8
  • IQR: 3.3
  • Lower_Fence: -0.45
  • Upper_Fence: 12.75
  • Count: 29
  • Mean: 6.13
  • StdDev: 1.67
20CVSS Range by Category: None
  • Q1: 8.2
  • Median: 8.2
  • Q3: 8.2
  • IQR: 0.0
  • Lower_Fence: 8.2
  • Upper_Fence: 8.2
  • Count: 1
  • Mean: 8.2
  • StdDev: N/A
21CVSS Range by Category: Privilege Elevation
  • Q1: 7.0
  • Median: 7.5
  • Q3: 7.8
  • IQR: 0.8
  • Lower_Fence: 5.8
  • Upper_Fence: 9.0
  • Count: 103
  • Mean: 7.48
  • StdDev: 0.91
22CVSS Range by Category: Remote Code Execution
  • Q1: 7.8
  • Median: 8.8
  • Q3: 8.8
  • IQR: 1.0
  • Lower_Fence: 6.3
  • Upper_Fence: 10.3
  • Count: 131
  • Mean: 8.35
  • StdDev: 0.66
23CVSS Range by Category: Spoofing
  • Q1: 4.85
  • Median: 6.5
  • Q3: 6.5
  • IQR: 1.65
  • Lower_Fence: 2.37
  • Upper_Fence: 8.98
  • Count: 27
  • Mean: 5.87
  • StdDev: 1.24
24CVSS Range by Category: Tampering
  • Q1: 6.8
  • Median: 6.8
  • Q3: 6.8
  • IQR: 0.0
  • Lower_Fence: 6.8
  • Upper_Fence: 6.8
  • Count: 1
  • Mean: 6.8
  • StdDev: N/A
25Cve Category Distribution Raw Counts
  • remote_code_execution: 131
  • privilege_elevation: 103
  • denial_of_service: 35
  • disclosure: 31
  • chromium-based: 31
  • feature_bypass: 29
  • spoofing: 27
  • none: 4
  • tampering: 1
26% of RCE CVEs33.42
27% of EOP CVEs26.28
28% of DoS CVEs8.93
29% of Disclosure CVEs7.91
30% of Spoofing CVEs6.89
31% of Tampering CVEs0.26
32% of Feature Bypass CVEs7.4
33Top Vulnerability Categoryremote_code_execution
34CVE Vulnerability Distributions: Remote Code Execution
  • count: 131
  • percentage: 33.42
35CVE Vulnerability Distributions: Privilege Elevation
  • count: 103
  • percentage: 26.28
36CVE Vulnerability Distributions: Denial Of Service
  • count: 35
  • percentage: 8.93
37CVE Vulnerability Distributions: Disclosure
  • count: 31
  • percentage: 7.91
38CVE Vulnerability Distributions: Chromium-Based
  • count: 31
  • percentage: 7.91
39CVE Vulnerability Distributions: Feature Bypass
  • count: 29
  • percentage: 7.4
40CVE Vulnerability Distributions: Spoofing
  • count: 27
  • percentage: 6.89
41CVE Vulnerability Distributions: None
  • count: 4
  • percentage: 1.02
42CVE Vulnerability Distributions: Tampering
  • count: 1
  • percentage: 0.26
43Network Vector50.0
44Local Vector38.52
45Adjacent Vector2.3
46Physical Vector8.16
47No User Action51.53
48User Action Required48.47
49No Privs Required Pct63.78
50Low Privileges Required33.93
51High Privileges Required2.3
52Low Attack Complexity85.46
53High Attack Complexity13.52
54High Risk CVEs0
55High Risk Cves[ ]
56Exploited Count KevN/A
57Exploited Pct KevN/A
58Top 3 Affected Builds
Build #1
  • Build Version: 10.0.26100.2894
  • Count: 122
Build #2
  • Build Version: 10.0.22631.4751
  • Count: 121
Build #3
  • Build Version: 10.0.22621.4751
  • Count: 121
59Cwe Category Distribution
  • memory_safety: 174
  • race_concurrency: 5
  • improper_access_control: 29
  • input_validation_injection: 22
  • cryptographic_issues: 0
  • configuration_weakness: 0
  • logic_state_errors: 0
  • none: 185
60Top Common WeaknessCWE-122
61Top 3 CWEs Coverage48.3
62Memory Safety Bugs174
63Logic State Errors0
64Race Concurrency Count5
65Improper Access Control Count29
66Input Validation Injection Count22
67Cryptographic Issues Count0
68Configuration Weakness Count0
69Memory Safety vs Logic BugsInf:1 (No Logic)
70Count of newly seen CWEs0
71Typical Patch Delay0.0
72Patched within 7 days93.57
73Patched within 30 days96.66
74Exploited Before PatchedN/A
75Most Affected Product(s)Windows 11 24h2 x64
76Percentage of missing key data0.72
77Total CVE Records Processed392
78Spotlight Cwe Slot 1
  • cwe_id_raw: CWE-416
  • display_cwe_label: CWE-416: Use After Free
  • count: 2
  • avg_cvss: 9.8
  • predominant_category_raw: remote_code_execution
  • display_predominant_category: Remote Code Execution
79Spotlight Cwe Slot 2
  • cwe_id_raw: CWE-290
  • display_cwe_label: CWE-290: Unknown CWE Name
  • count: 1
  • avg_cvss: 9.9
  • predominant_category_raw: spoofing
  • display_predominant_category: Spoofing
80Spotlight Cwe Slot 3
  • cwe_id_raw: CWE-288
  • display_cwe_label: CWE-288: Unknown CWE Name
  • count: 1
  • avg_cvss: 9.8
  • predominant_category_raw: remote_code_execution
  • display_predominant_category: Remote Code Execution
81Spotlight Cwe Slot 4
  • cwe_id_raw: CWE-303
  • display_cwe_label: CWE-303: Unknown CWE Name
  • count: 1
  • avg_cvss: 9.8
  • predominant_category_raw: privilege_elevation
  • display_predominant_category: Privilege Elevation

A. Data Collection Methodology

The data used to generate this report was collected from the National Vulnerability Database (NVD) and the Microsoft Security Response Center (MSRC).

The NVD is a repository of information about vulnerabilities in software products. It is a collaborative effort between the U.S. government and the private sector to provide a single source of information about vulnerabilities in software products.

Information regarding Common Weakness Enumeration (CWE) identifiers associated with CVEs is primarily drawn from data provided by the National Vulnerability Database (NVD). For detailed definitions, descriptions, and hierarchical categorizations of these CWEs, this report refers to the official MITRE CWE™ list and classifications available at cwe.mitre.org.

B. Statistics Notes

Several assumptions were used in order to complete the calculations of various metrics presented in this report.

For example, the CVSS score of a CVE is calculated based on the CVSS v3.1 formula, which takes into account the base score, temporal score, and environmental score. The base score is calculated based on the severity of the vulnerability, the attack vector, the attack complexity, the privileges required, the user interaction required, and the scope of the vulnerability. The temporal score is calculated based on the confidentiality, integrity, and availability impact of the vulnerability. The environmental score is calculated based on the confidentiality, integrity, and availability impact of the vulnerability, as well as the attack vector, the attack complexity, the privileges required, the user interaction required, and the scope of the vulnerability.

The metric "Worst Case CVEs" was based on a weighted average with the following properties:

This risk score model is designed to prioritize vulnerabilities by emphasizing their exploitability characteristics over sheer severity. The weights assigned to each CVSS metric component in the formula are derived from a qualitative analysis considering the following key factors:

Weight Derivation Factors:
  1. Analysis of exploit prevalence and historical data on vulnerabilities exploited in the wild.
  2. Prioritization guidelines and insights from Microsoft's Security Response Center (MSRC) and similar industry bodies.
  3. The relative importance and contribution of each CVSS vector component to the likelihood of successful automated attacks.
Risk Score Formula (LaTeX Notation):

General Form:

R = w_{AV} \cdot V_{AV} + w_{AC} \cdot V_{AC} + w_{PR} \cdot V_{PR} + w_{UI} \cdot V_{UI}

Summation Notation:

\text{RiskScore} (R) = \sum_{i \in \{\text{AV, AC, PR, UI}\}} w_i \cdot V_i

Where:

  • R represents the calculated Risk Score.
  • wi denotes the weight assigned to each CVSS component i:
    • Attack Vector (wAV): 0.35 (reflecting its high impact on exploitability)
    • Attack Complexity (wAC): 0.25 (secondary in importance for exploitability)
    • Privileges Required (wPR): 0.20
    • User Interaction (wUI): 0.20
  • Vi represents the normalized value (typically ranging from 0 to 1) for each corresponding CVSS component i (Attack Vector, Attack Complexity, Privileges Required, User Interaction), derived from the CVSS v3.x standard.

This weighted average approach allows for a nuanced assessment of risk, focusing on the practical aspects of how a vulnerability might be leveraged.

Understanding Boxplots and Outlier Detection

Boxplots (or box-and-whisker plots) are graphical representations that display the distribution of a dataset based on a five-number summary: minimum, first quartile (Q1), median (Q2), third quartile (Q3), and maximum. They provide a concise visual summary of key statistical measures presented in this report.

  • The central "box" spans the Interquartile Range (IQR), which is the range between the first quartile (Q1, representing the 25th percentile) and the third quartile (Q3, representing the 75th percentile). This box contains the middle 50% of the data.
  • A line within the box marks the median (Q2, or 50th percentile) of the dataset.
  • "Whiskers" extend from the ends of the box. In this report, they indicate the range of data within 1.5 times the IQR beyond the first and third quartiles.

For identifying potential outliers, the following standard statistical method, often referred to as Tukey's fences, is employed:

  • The Interquartile Range (IQR) is calculated as: IQR = Q3 - Q1.
  • The Lower Fence (or inner fence) is established at: LF = Q1 - (1.5 * IQR).
  • The Upper Fence (or inner fence) is established at: UF = Q3 + (1.5 * IQR).

Data points that fall below the Lower Fence or above the Upper Fence are considered potential outliers and are typically plotted as individual points beyond the whiskers. The whiskers themselves then extend to the minimum and maximum data values that lie within these calculated fences (i.e., the smallest data point greater than or equal to LF, and the largest data point less than or equal to UF).

Data Selection from Multiple NVD Signing Authorities

A single Common Vulnerabilities and Exposures (CVE) entry within the National Vulnerability Database (NVD) can sometimes include multiple sets of Common Vulnerability Scoring System (CVSS) data. This occurs when different organizations (signing authorities, such as NVD itself, software vendors like Microsoft, or other CNA - CVE Numbering Authorities) provide their own assessment of a vulnerability.

For consistency and to ensure a conservative (worst-case) perspective in this report, when multiple CVSS scores are present for a single CVE, the highest available CVSS Base Score is selected for all analyses and metric calculations. The full vector string associated with this highest score is also adopted.

Example:

Consider a hypothetical CVE, CVE-2024-ABCDE, with the following CVSS data provided by different authorities:

  • NVD (NIST) Assessment: CVSS Base Score 7.8 (Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
  • Vendor X Assessment: CVSS Base Score 8.1 (Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  • Vendor Y Assessment: CVSS Base Score 7.5 (Vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)

In this scenario, the data used for this report would be from Vendor X: a CVSS Base Score of 8.1 and its corresponding vector string, as this represents the highest severity assessment among the available sources.

Patch Delay Calculation and Assumptions

The "Patch Delay" metric presented in this report quantifies the time elapsed between Microsoft's initial public disclosure of a CVE and its subsequent publication in the National Vulnerability Database (NVD). It is calculated as:

Patch Delay = NVD Published Date - Microsoft CVE Published Date

The calculation relies on the following key assumptions regarding the date fields used:

  • Microsoft CVE Published Date: This is sourced from the publishedDate field in Microsoft's Security Update Guide (SUG) or MSRC API data. It is assumed to represent the date Microsoft formally announced or publicly disclosed the vulnerability.
  • NVD Published Date: This refers to the publishedDate field associated with the CVE entry in the NVD. It is assumed to approximate the date when a patch or mitigation was officially documented and made widely available, often aligning with the NVD's own publication timeline after receiving and processing the CVE information.

It is important to acknowledge that this method provides an empirical estimate of patch delay. The dates used are proxies and may not always perfectly correspond to the precise moment of initial vulnerability announcement versus actual patch availability. Factors such as coordination between vendors and NVD, processing times, and differing definitions of "published" can introduce variability. Therefore, while practical for trend analysis, this metric rests on an interpretative foundation regarding the significance of these specific date fields.

CWE Grouping for Thematic Analysis

To facilitate a higher-level understanding of prevalent vulnerability types, individual Common Weakness Enumeration (CWE) identifiers are mapped to broader, feature-engineered root cause categories. This thematic grouping helps in identifying trends and patterns in the types of software weaknesses exploited. These categories are defined within the project's analytical framework and include:

  • Memory Safety: Encompasses vulnerabilities related to how software manages computer memory, such as buffer overflows, use-after-free, and null pointer dereferences. These can lead to crashes, arbitrary code execution, or information disclosure.
  • Input Validation and Injection: Covers weaknesses where software does not properly validate, sanitize, or neutralize input from users or external sources. This includes SQL injection, Cross-Site Scripting (XSS), command injection, and path traversal.
  • Improper Access Control: Relates to failures in enforcing permissions and privileges, allowing unauthorized actors to access or modify resources, or escalate their privileges. Examples include missing authorization checks or insecure direct object references.
  • Race Conditions and Concurrency: Arises from incorrect handling of sequences or timing of operations in multi-threaded or distributed environments, potentially leading to data corruption, deadlocks, or exploitation of time-of-check to time-of-use (TOCTOU) flaws.
  • Cryptographic Issues: Includes problems with the use of cryptographic algorithms, such as weak ciphers, improper key management, or missing encryption for sensitive data, potentially exposing information or compromising system integrity.
  • Configuration Weaknesses: Stems from insecure default settings, misconfigurations of software or systems, or overly permissive configurations that can be exploited by attackers.
  • Logic and State Errors: Pertains to flaws in the design or implementation of business logic or state management within an application, leading to unexpected behavior that can be leveraged for malicious purposes.

This categorization aids in strategic discussions about mitigation efforts and common pitfalls in software development.