| Date | Source | Article |
|---|---|---|
| 2025-12-22 | ESET WeLiveSecurity | Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component CVE-2025-50165 |
Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.
| CVE | CVSS | Affected |
|---|---|---|
| CVE-2025-50165 | 9.8 Critical | Microsoft Windows 11 Version 24H2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
| CVE-2025-53766 | 9.8 Critical | Microsoft Microsoft Office for Android Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
| CVE-2025-53778 | 8.8 High | Microsoft Windows 10 Version 1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-53731 | 8.4 High | Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-53733 | 8.4 High | Microsoft Microsoft 365 Apps for Enterprise Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-53740 | 8.4 High | Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-53784 | 8.4 High | Microsoft Microsoft 365 Apps for Enterprise Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-50177 | 8.1 High | Microsoft Windows 10 Version 1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50176 | 7.8 High | Microsoft Windows 11 version 22H2 Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally. |
| CVE-2025-48807 | 6.7 Medium | Microsoft Windows 10 Version 1607 Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally. |
Extracted from the publication text. Each CVE links to its tracked detail page.
Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.