You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
network exploits
About this tag
Network exploits on Windows systems are a recurring concern, as shown by recent vulnerabilities affecting core components. CVE-2025-50165 is a high-risk remote code execution flaw in the Windows Graphics Component that can be triggered over a network via an untrusted pointer dereference. CVE-2025-30390 involves improper authorization in Azure Machine Learning, allowing privilege escalation over a network. CVE-2025-49659 is a privilege escalation vulnerability in the Windows Transport Driver Interface (TDI) driver due to a buffer over-read. CVE-2025-48819 affects the UPnP Device Host, enabling privilege escalation over an adjacent network through improperly locked memory. CVE-2025-49670 targets the Routing and Remote Access Service (RRAS), posing risks to VPN and network infrastructure. These examples highlight the importance of patching and layered defenses against network-based attacks.
A newly disclosed vulnerability in the Microsoft Graphics Component, tracked as CVE-2025-50165, is being treated as a high-risk remote code execution (RCE) issue that can allow an unauthenticated attacker to execute arbitrary code over a network by triggering an untrusted pointer dereference in...
In April 2025, Microsoft disclosed a critical security vulnerability in Azure Machine Learning (Azure ML), identified as CVE-2025-30390. This flaw, stemming from improper authorization mechanisms, allows authorized attackers to escalate their privileges over a network, potentially compromising...
A critical security vulnerability, identified as CVE-2025-49659, has been discovered in the Windows Transport Driver Interface (TDI) Translation Driver, specifically within the tdx.sys component. This flaw allows authorized attackers to elevate their privileges locally by exploiting a buffer...
The Windows Universal Plug and Play (UPnP) Device Host has been identified with a critical vulnerability, designated as CVE-2025-48819. This flaw allows an authorized attacker to elevate their privileges over an adjacent network by exploiting sensitive data stored in improperly locked memory...
Windows Routing and Remote Access Service (RRAS) has long served as a strategic component in the network backbone of organizations, facilitating VPNs, network address translation, and secure dial-up connections across Windows-based environments. Yet, its critical infrastructure role continues to...