
CVE-2022-41628
https://notcve.org/view.php?id=CVE-2022-41628
10 May 2023 — Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access. • https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00802.html • CWE-427: Uncontrolled Search Path Element •

CVE-2022-41687
https://notcve.org/view.php?id=CVE-2022-41687
10 May 2023 — Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access. • https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00802.html • CWE-276: Incorrect Default Permissions CWE-277: Insecure Inherited Permissions •

CVE-2023-21808 – .NET and Visual Studio Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-21808
14 Feb 2023 — .NET and Visual Studio Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21808 • CWE-416: Use After Free •

CVE-2023-21722 – .NET Framework Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2023-21722
14 Feb 2023 — .NET Framework Denial of Service Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21722 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2022-38396
https://notcve.org/view.php?id=CVE-2022-38396
03 Feb 2023 — HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation of privilege via execution of certain files outside the restricted path. This potential vulnerability was remediated starting with Windows 10 versions 21H2 on October 31, 2021. • https://support.hp.com/ie-en/document/ish_7620368-7620413-16 •

CVE-2022-26934 – Windows Graphics Component Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2022-26934
10 May 2022 — Windows Graphics Component Information Disclosure Vulnerability Una vulnerabilidad de Divulgación de Información de Windows Graphics Component. Este ID de CVE es diferente de CVE-2022-22011, CVE-2022-29112 • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26934 •

CVE-2022-26925 – Microsoft Windows LSA Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2022-26925
10 May 2022 — Windows LSA Spoofing Vulnerability Una vulnerabilidad de Falsificación de Windows LSA Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925 • CWE-306: Missing Authentication for Critical Function •

CVE-2022-26923 – Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-26923
10 May 2022 — Active Directory Domain Services Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Active Directory Domain Services This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of Microsoft Windows Active Directory Certificate Services. Authentication is required to exploit this vulnerability. The specific flaw exists within the issuance of certificates. By including crafted data in a certificate request, an attacker can obtain a ... • https://packetstorm.news/files/id/180778 • CWE-295: Improper Certificate Validation •

CVE-2022-24521 – Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-24521
15 Apr 2022 — Windows Common Log File System Driver Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows Common Log File System Driver. Este ID de CVE es diferente de CVE-2022-24481 Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24521 • CWE-787: Out-of-bounds Write •

CVE-2022-26904 – Microsoft Windows User Profile Service Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2022-26904
11 Apr 2022 — Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •