Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate…
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth…
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information ove…
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
Payment Orchestrator Service Elevation of Privilege Vulnerability
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.