Show filters
190 Total Results
Displaying 11-20 of 190
Sort by:
Attacker Value
Unknown

CVE-2021-26862

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
Windows Installer Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-26889

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
Windows Update Stack Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-26887

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
<p>An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder.</p> <p>To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data.</p> <p>This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the <strong>FAQ</strong> section of this CVE for configuration guidance.</p>
0
Attacker Value
Unknown

CVE-2021-26866

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
Windows Update Service Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-26873

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
Windows User Profile Service Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2021-3310

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
Attacker Value
Unknown

CVE-2020-4717

Disclosure Date: March 09, 2021 (last updated February 22, 2025)
A vulnerability exists in IBM SPSS Modeler Subscription Installer that allows a user with create symbolic link permission to write arbitrary file in another protected path during product installation. IBM X-Force ID: 187727.
Attacker Value
Unknown

CVE-2021-24084

Disclosure Date: February 25, 2021 (last updated February 22, 2025)
Windows Mobile Device Management Information Disclosure Vulnerability
0
Attacker Value
Unknown

CVE-2020-12878

Disclosure Date: February 18, 2021 (last updated February 22, 2025)
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.
Attacker Value
Unknown

CVE-2021-26720

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.