CVE-2022-26904 – Microsoft Windows User Profile Service Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-26904
Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 https://github.com/rmusser01/SuperProfile https://web.archive.org/web/20220222105232/https://halove23.blogspot.com/2022/02/blog-post.html https://github.com/klinix5/ProfSvcLPE/blob/main/write-up.docx • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2022-22718 – Microsoft Windows Print Spooler Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-22718
Windows Print Spooler Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Windows Print Spooler. Este ID de CVE es diferente de CVE-2022-21997, CVE-2022-21999, CVE-2022-22717 Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. • https://github.com/ahmetfurkans/CVE-2022-22718 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22718 •
CVE-2022-21919 – Microsoft Windows User Profile Service Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-21919
Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service. Este ID de CVE es diferente de CVE-2022-21895 Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21919 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21919 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2022-21871 – Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2022-21871
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Microsoft Diagnostics Hub Standard Collector Runtime • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21871 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21871 •
CVE-2021-41379 – Microsoft Windows Installer Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2021-41379
Windows Installer Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios del instalador de Windows This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer service. By creating a junction, an attacker can abuse the service to delete a file or directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41379 https://www.zerodayinitiative.com/advisories/ZDI-21-1308 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •