CVE-2022-22047 – Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-22047
12 Jul 2022 — Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios de Windows CSRSS. Este ID de CVE es diferente de CVE-2022-22026, CVE-2022-22049 Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22047 • CWE-426: Untrusted Search Path •
CVE-2022-30190 – Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-30190
31 May 2022 — A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vu... • https://packetstorm.news/files/id/167438 • CWE-610: Externally Controlled Reference to a Resource in Another Sphere •
CVE-2022-26925 – Microsoft Windows LSA Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2022-26925
10 May 2022 — Windows LSA Spoofing Vulnerability Una vulnerabilidad de Falsificación de Windows LSA Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925 • CWE-306: Missing Authentication for Critical Function •
CVE-2022-26923 – Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-26923
10 May 2022 — Active Directory Domain Services Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Active Directory Domain Services This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of Microsoft Windows Active Directory Certificate Services. Authentication is required to exploit this vulnerability. The specific flaw exists within the issuance of certificates. By including crafted data in a certificate request, an attacker can obtain a ... • https://packetstorm.news/files/id/180778 • CWE-295: Improper Certificate Validation •
CVE-2022-24521 – Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-24521
15 Apr 2022 — Windows Common Log File System Driver Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows Common Log File System Driver. Este ID de CVE es diferente de CVE-2022-24481 Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24521 •
CVE-2022-26904 – Microsoft Windows User Profile Service Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-26904
11 Apr 2022 — Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2022-22718 – Microsoft Windows Print Spooler Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-22718
09 Feb 2022 — Windows Print Spooler Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Windows Print Spooler. Este ID de CVE es diferente de CVE-2022-21997, CVE-2022-21999, CVE-2022-22717 Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. • https://github.com/ahmetfurkans/CVE-2022-22718 •
CVE-2022-21971 – Microsoft Windows Runtime Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-21971
09 Feb 2022 — Windows Runtime Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota en Windows Runtime Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. • https://github.com/0vercl0k/CVE-2022-21971 • CWE-824: Access of Uninitialized Pointer •
CVE-2022-21919 – Microsoft Windows User Profile Service Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-21919
11 Jan 2022 — Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service. Este ID de CVE es diferente de CVE-2022-21895 Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21919 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2022-21882 – Microsoft Win32k Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-21882
11 Jan 2022 — Win32k Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Win32k. Este ID de CVE es diferente de CVE-2022-21887 Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. • https://packetstorm.news/files/id/166169 • CWE-787: Out-of-bounds Write •