Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Affected productsWindows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems, Windows 11 Version 25H2 for ARM64-based Systems
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Affected productsOffice Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Affected productsWindows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Affected productsMicrosoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Affected productsazl3 kata-containers 3.32.0.kata0-2 on Azure Linux 3.0, azl3 rust 1.90.0-10 on Azure Linux 3.0, azl3 cloud-hypervisor 51.1.101-2 on Azure Linux 3.0, azl3 rust 1.75.0-30 on Azure Linux 3.0
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.