18 results (0.012 seconds)

CVSS: 7.8EPSS: 1%CPEs: 96EXPL: 0

14 Feb 2023 — .NET and Visual Studio Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21808 • CWE-416: Use After Free •

CVSS: 5.0EPSS: 0%CPEs: 71EXPL: 0

14 Feb 2023 — .NET Framework Denial of Service Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21722 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 6.5EPSS: 4%CPEs: 26EXPL: 0

10 May 2022 — Windows Graphics Component Information Disclosure Vulnerability Una vulnerabilidad de Divulgación de Información de Windows Graphics Component. Este ID de CVE es diferente de CVE-2022-22011, CVE-2022-29112 • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26934 •

CVSS: 9.3EPSS: 50%CPEs: 19EXPL: 0

10 May 2022 — Windows LSA Spoofing Vulnerability Una vulnerabilidad de Falsificación de Windows LSA Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26925 • CWE-306: Missing Authentication for Critical Function •

CVSS: 9.3EPSS: 91%CPEs: 14EXPL: 8

10 May 2022 — Active Directory Domain Services Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Active Directory Domain Services This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of Microsoft Windows Active Directory Certificate Services. Authentication is required to exploit this vulnerability. The specific flaw exists within the issuance of certificates. By including crafted data in a certificate request, an attacker can obtain a ... • https://packetstorm.news/files/id/180778 • CWE-295: Improper Certificate Validation •

CVSS: 10.0EPSS: 3%CPEs: 19EXPL: 0

15 Apr 2022 — Windows Common Log File System Driver Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows Common Log File System Driver. Este ID de CVE es diferente de CVE-2022-24481 Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24521 • CWE-787: Out-of-bounds Write •

CVSS: 10.0EPSS: 12%CPEs: 19EXPL: 0

11 Apr 2022 — Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26904 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 7.8EPSS: 5%CPEs: 19EXPL: 1

09 Feb 2022 — Windows Print Spooler Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios en Windows Print Spooler. Este ID de CVE es diferente de CVE-2022-21997, CVE-2022-21999, CVE-2022-22717 Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. • https://github.com/ahmetfurkans/CVE-2022-22718 •

CVSS: 9.3EPSS: 86%CPEs: 9EXPL: 3

09 Feb 2022 — Windows Runtime Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota en Windows Runtime Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. • https://github.com/0vercl0k/CVE-2022-21971 • CWE-824: Access of Uninitialized Pointer •

CVSS: 9.3EPSS: 0%CPEs: 19EXPL: 0

11 Jan 2022 — Windows User Profile Service Elevation of Privilege Vulnerability Una vulnerabilidad de Elevación de Privilegios en Windows User Profile Service. Este ID de CVE es diferente de CVE-2022-21895 Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21919 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •