231 results (0.095 seconds)

CVSS: 7.8EPSS: 2%CPEs: 26EXPL: 1

08 Apr 2025 — Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. • https://github.com/encrypter15/CVE-2025-29824 • CWE-416: Use After Free •

CVSS: 7.8EPSS: 1%CPEs: 26EXPL: 1

11 Mar 2025 — Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. • https://github.com/airbus-cert/cve-2025-24985 • CWE-122: Heap-based Buffer Overflow CWE-190: Integer Overflow or Wraparound •

CVSS: 10.0EPSS: 7%CPEs: 26EXPL: 1

14 Jan 2025 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability • https://github.com/git-account7/CVE-2025-21307 • CWE-416: Use After Free •

CVSS: 10.0EPSS: 84%CPEs: 26EXPL: 7

10 Dec 2024 — Windows Common Log File System Driver Elevation of Privilege Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. • https://packetstorm.news/files/id/190585 • CWE-122: Heap-based Buffer Overflow •

CVSS: 7.8EPSS: 0%CPEs: 13EXPL: 1

10 Dec 2024 — Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability The Microsoft Windows kernel is susceptible to a false file immutability attack on registry hives via the Cloud Filter API. • https://packetstorm.news/files/id/183324 • CWE-820: Missing Synchronization •

CVSS: 7.0EPSS: 0%CPEs: 25EXPL: 1

08 Oct 2024 — Windows Kernel-Mode Driver Elevation of Privilege Vulnerability • https://github.com/jayesther/KTM_POCS • CWE-416: Use After Free •

CVSS: 8.8EPSS: 4%CPEs: 10EXPL: 4

25 Sep 2024 — Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers. • https://packetstorm.news/files/id/182012 • CWE-347: Improper Verification of Cryptographic Signature •

CVSS: 8.8EPSS: 0%CPEs: 10EXPL: 1

25 Sep 2024 — Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers. • https://packetstorm.news/files/id/182012 • CWE-347: Improper Verification of Cryptographic Signature •

CVSS: 9.0EPSS: 78%CPEs: 25EXPL: 1

13 Aug 2024 — Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability • https://github.com/Dor00tkit/CVE-2024-38144 • CWE-190: Integer Overflow or Wraparound •

CVSS: 10.0EPSS: 71%CPEs: 25EXPL: 3

13 Aug 2024 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. • https://packetstorm.news/files/id/191180 • CWE-416: Use After Free •