CVE-2023-21767 – Windows Overlay Filter Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21767
Windows Overlay Filter Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios del filtro de superposición de Windows • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21767 • CWE-20: Improper Input Validation •
CVE-2023-21771 – Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21771
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios del Administrador de sesión local (LSM) de Windows • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21771 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-591: Sensitive Data Storage in Improperly Locked Memory •
CVE-2023-21746 – Windows NTLM Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-21746
Windows NTLM Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21746 •
CVE-2023-21758 – Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2023-21758
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Vulnerabilidad de denegación de servicio de extensión de intercambio de claves de Internet (IKE) de Windows This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability. The specific flaw exists within the IKEEXT service, which listens on UDP ports 500 and 4500. A crafted Vendor ID payload can cause a null pointer dereference. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21758 • CWE-476: NULL Pointer Dereference •
CVE-2023-21757 – Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2023-21757
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability Vulnerabilidad de denegación de servicio del protocolo de túnel de capa 2 de Windows (L2TP) • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21757 • CWE-476: NULL Pointer Dereference •