Show filters
833 Total Results
Displaying 11-20 of 833
Sort by:
Attacker Value
High
CVE-2024-49019
Disclosure Date: November 12, 2024 (last updated January 06, 2025)
Active Directory Certificate Services Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2024-38077
Disclosure Date: July 09, 2024 (last updated January 12, 2025)
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
2
Attacker Value
Very Low
CVE-2024-43452
Disclosure Date: November 12, 2024 (last updated January 06, 2025)
Windows Registry Elevation of Privilege Vulnerability
1
Attacker Value
Very Low
CVE-2024-49113
Disclosure Date: December 12, 2024 (last updated January 15, 2025)
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
1
Attacker Value
High
CVE-2024-35250
Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
1
Attacker Value
High
CVE-2024-30088
Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Windows Kernel Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2024-21302
Disclosure Date: August 08, 2024 (last updated September 18, 2024)
Summary:
Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS.
Microsoft is developing a security update to mitigate this threat, but it is not yet available. Guidance to help customers reduce the risks associated with this vulnerability and to protect their systems until the mitigation is available in a Windows security update is provided in the Recommended Actions section of this CVE.
This CVE will be updated when the mitigation is available in a Windows security update. We highly encourage customers to subscribe to Security Upda…
2
Attacker Value
Unknown
CVE-2024-38080
Disclosure Date: July 09, 2024 (last updated January 28, 2025)
Windows Hyper-V Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2023-36033
Disclosure Date: November 14, 2023 (last updated January 24, 2025)
Windows DWM Core Library Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2024-38202
Disclosure Date: August 08, 2024 (last updated January 12, 2025)
Summary
Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacker attempting to exploit this vulnerability requires additional interaction by a privileged user to be successful.
Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this …
1