Page 8 of 976 results (0.018 seconds)

CVSS: 7.8EPSS: 0%CPEs: 14EXPL: 0

Windows Feedback Hub Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows Feedback Hub This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the DiagTrack service. By creating a symbolic link, an attacker can abuse the service to delete a directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42280 https://www.zerodayinitiative.com/advisories/ZDI-21-1307 • CWE-269: Improper Privilege Management •

CVSS: 7.5EPSS: 5%CPEs: 14EXPL: 0

Chakra Scripting Engine Memory Corruption Vulnerability Una vulnerabilidad de corrupción de memoria en Chakra Scripting Engine • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42279 • CWE-787: Out-of-bounds Write •

CVSS: 7.8EPSS: 0%CPEs: 17EXPL: 0

Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Diagnostics Hub Standard Collector This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Microsoft Diagnostics Hub Standard Collector Service. By creating a symbolic link, an attacker can abuse the service to delete a directory. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42277 https://www.zerodayinitiative.com/advisories/ZDI-21-1306 • CWE-269: Improper Privilege Management •

CVSS: 7.8EPSS: 10%CPEs: 14EXPL: 0

Microsoft Windows Media Foundation Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota de Microsoft Windows Media Foundation • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42276 •

CVSS: 8.8EPSS: 1%CPEs: 21EXPL: 0

Microsoft COM for Windows Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota de Microsoft COM para Windows • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42275 •