CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network. |
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. |
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. |
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. |
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. |
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. |
An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users. |
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. |
Use after free in Xbox allows an authorized attacker to elevate privileges locally. |
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. |
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. |
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. |
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. |
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. |