Security
Headlines
HeadlinesLatestCVEs

Latest News

CVE-2025-29971: Web Threat Defense (WTD.sys) Denial of Service Vulnerability

Out-of-bounds read in Windows Transport Security Layer (TLS) allows an unauthorized attacker to deny service over a network.

Microsoft Security Response Center
#vulnerability#web#windows#dos#auth#ssl#Web Threat Defense (WTD.sys)#Security Vulnerability
CVE-2025-30375: Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-29966: Remote Desktop Client Remote Code Execution Vulnerability

**How could an attacker exploit this vulnerability?** In the case of a Remote Desktop connection, an attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the RDP client machine when a victim connects to the attackers server with the vulnerable Remote Desktop Client.