Page 111 of 1548 results (0.011 seconds)

CVSS: 7.8EPSS: 0%CPEs: 9EXPL: 0

Windows Services and Controller App Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios de Services y Controller App de Windows The access limit check for non-local admins when accessing the SCM remotely can be bypassed by requesting MAXIMUM_ALLOWED, leading to gaining access to start services etc. • http://packetstormsecurity.com/files/162157/Microsoft-Windows-SCM-Remote-Access-Check-Limit-Bypass-Privilege-Escalation.html https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27086 • CWE-863: Incorrect Authorization •

CVSS: 6.3EPSS: 0%CPEs: 12EXPL: 0

Windows Media Photo Codec Information Disclosure Vulnerability Una vulnerabilidad de Divulgación de Información de Media Photo Codec de Windows • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27079 •

CVSS: 7.8EPSS: 0%CPEs: 16EXPL: 0

Win32k Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios de Win32k. Este ID de CVE es diferente de CVE-2021-28310 • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27072 •

CVSS: 5.5EPSS: 0%CPEs: 8EXPL: 0

Windows Overlay Filter Information Disclosure Vulnerability Una Vulnerabilidad de Divulgación de Información de Overlay Filter de Windows • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26417 •

CVSS: 7.8EPSS: 0%CPEs: 19EXPL: 1

Windows Installer Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios de Windows Installer. Este ID de CVE es diferente de CVE-2021-28440 This vulnerability allows local attackers to write data to arbitrary files on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer service. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an administrator. • https://github.com/adenkiewicz/CVE-2021-26415 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26415 https://www.zerodayinitiative.com/advisories/ZDI-21-409 • CWE-20: Improper Input Validation •