High - CVE-2025-47178 - Improper neutralization of special elements...
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent...
High - CVE-2025-47972 - Concurrent execution using shared resource with...
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over...
Medium - CVE-2025-47980 - Exposure of sensitive information to an...
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.