Products: .NET · ASP.NET Core · Azure CycleCloud 8.9.1 · Azure Kubernetes Service · Azure Migrate · Microsoft .NET Framework · Microsoft 365 Apps for Enterprise · Microsoft Azure Functions · Microsoft Configuration Manager · Microsoft Dataverse · Microsoft Defender for IoT · Microsoft Edge (Chromium-based) · Microsoft Entra · Microsoft Exchange Server 2016 Cumulative Update 23 · Microsoft Exchange Server 2019 Cumulative Update 13 · Microsoft Exchange Server 2019 Cumulative Update 14 · Microsoft Exchange Server 2019 Cumulative Update 15 · Microsoft Exchange Server Subscription Edition RTM · Microsoft ODBC Driver 17 for SQL Server on Linux · Microsoft ODBC Driver 17 for SQL Server on MacOS
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 withou
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedd
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through ufo
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to cre
The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from cross-origin redirect target
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause U
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK mess
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated WebSocket connections. The handler stores per-connection protocol objects in mutab
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an existing in-memory session object if that session_id already exists. If a prior session
Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows 11 Version 25H2Windows 11 version 26H1Windows Server 2016
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to security risks. The function lacks `has
ASP.NET CoreMicrosoft Visual Studio 2022 version 17.10Microsoft Visual Studio 2022 version 17.12Microsoft Visual Studio 2022 version 17.14
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
Windows Server 2012Windows Server 2012 (Server Core installation)Windows Server 2012 R2Windows Server 2012 R2 (Server Core installation)Windows Server 2016Windows Server 2016 (Server Core installation)Windows Server 2019Windows Server 2019 (Server Core installation)Windows Server 2022Windows Server 2022, 23H2 Edition (Server Core installation)
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
Microsoft is preparing and fully testing a comprehensive update to address this vulne
ASP.NET CoreMicrosoft.AspNetCore.App.Runtime.linux-armMicrosoft.AspNetCore.App.Runtime.linux-arm64Microsoft.AspNetCore.App.Runtime.linux-musl-armMicrosoft.AspNetCore.App.Runtime.linux-musl-arm64Microsoft.AspNetCore.App.Runtime.linux-musl-x64Microsoft.AspNetCore.App.Runtime.linux-x64Microsoft.AspNetCore.App.Runtime.osx-arm64Microsoft.AspNetCore.App.Runtime.osx-x64Microsoft.AspNetCore.App.Runtime.win-arm
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows Server 2008 R2 Service Pack 1
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
This vulnerability has already been mitigated in the service and all affected customers have been notified. This update ad
Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows Server 2008 R2 Service Pack 1
Microsoft Exchange Server 2016 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 14
Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 21H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2
Windows TCP/IP Remote Code Execution Vulnerability
.NETMicrosoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.8Microsoft Visual Studio 2022 version 17.9PowerShell 7.3PowerShell 7.4
.NET and Visual Studio Denial of Service Vulnerability
Microsoft Exchange Server 2016 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft Exchange Server Elevation of Privilege Vulnerability
.NETASP.NET CoreMicrosoft Visual Studio 2022 version 17.2Microsoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.7