CVE-2023-21680 – Windows Win32k Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21680
Windows Win32k Elevation of Privilege Vulnerability Vulnerabilidad de escalada de privilegios en Windows Win32k This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the GreStartDocInternal function. By making crafted calls into this function, an attacker can overflow the reference counter of a bitmap object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21680 • CWE-416: Use After Free •
CVE-2023-21541 – Windows Task Scheduler Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21541
Windows Task Scheduler Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21541 •
CVE-2023-21772 – Windows Kernel Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21772
Windows Kernel Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios del kernel de Windows The Microsoft Windows kernel suffers from multiple security issues in the key replication feature of registry virtualization. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21772 • CWE-125: Out-of-bounds Read CWE-269: Improper Privilege Management •
CVE-2023-21733 – Windows Bind Filter Driver Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21733
Windows Bind Filter Driver Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios del controlador del filtro de enlace de Windows • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21733 • CWE-122: Heap-based Buffer Overflow CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2023-21749 – Windows Kernel Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21749
Windows Kernel Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios del kernel de Windows The Microsoft Windows kernel registry has a SID table poisoning problem that leads to bad locking and other issues. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21749 • CWE-20: Improper Input Validation •