Page 128 of 649 results (0.006 seconds)

CVSS: 9.0EPSS: 5%CPEs: 14EXPL: 3

Active Directory Domain Services Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Active Directory Domain Services This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of Microsoft Windows Active Directory Certificate Services. Authentication is required to exploit this vulnerability. The specific flaw exists within the issuance of certificates. By including crafted data in a certificate request, an attacker can obtain a certificate that allows the attacker to authenticate to a domain controller with a high level of privilege. An attacker can leverage this vulnerability to escalate privileges and disclose stored credentials, leading to further compromise. An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM. • https://github.com/lsecqt/CVE-2022-26923-Powershell-POC https://github.com/r1skkam/TryHackMe-CVE-2022-26923 https://github.com/Gh-Badr/CVE-2022-26923 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26923 • CWE-295: Improper Certificate Validation •

CVSS: 7.8EPSS: 0%CPEs: 19EXPL: 0

Windows Common Log File System Driver Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows Common Log File System Driver. Este ID de CVE es diferente de CVE-2022-24481 Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24521 •

CVSS: 7.0EPSS: 0%CPEs: 19EXPL: 1

Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 https://github.com/rmusser01/SuperProfile https://web.archive.org/web/20220222105232/https://halove23.blogspot.com/2022/02/blog-post.html https://github.com/klinix5/ProfSvcLPE/blob/main/write-up.docx https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/local/cve_2022_26904_superprofile.rb • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 7.8EPSS: 0%CPEs: 19EXPL: 1

Windows Print Spooler Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Windows Print Spooler. Este ID de CVE es diferente de CVE-2022-21997, CVE-2022-21999, CVE-2022-22717 Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. • https://github.com/ahmetfurkans/CVE-2022-22718 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22718 •

CVSS: 9.3EPSS: 20%CPEs: 9EXPL: 3

Windows Runtime Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota en Windows Runtime Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. • https://github.com/0vercl0k/CVE-2022-21971 https://github.com/Malwareman007/CVE-2022-21971 https://github.com/tufanturhan/CVE-2022-21971-Windows-Runtime-RCE https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21971 • CWE-824: Access of Uninitialized Pointer •