Show filters
837 Total Results
Displaying 11-20 of 837
Sort by:
Attacker Value
Unknown

CVE-2024-43639

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Windows KDC Proxy Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38077

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Attacker Value
Very Low

CVE-2024-49113

Disclosure Date: December 12, 2024 (last updated February 27, 2025)
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Attacker Value
High

CVE-2024-35250

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Attacker Value
Very Low

CVE-2024-43452

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Windows Registry Elevation of Privilege Vulnerability
Attacker Value
High

CVE-2024-30088

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Kernel Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-21302

Disclosure Date: August 08, 2024 (last updated February 26, 2025)
Summary: Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. Microsoft is developing a security update to mitigate this threat, but it is not yet available. Guidance to help customers reduce the risks associated with this vulnerability and to protect their systems until the mitigation is available in a Windows security update is provided in the Recommended Actions section of this CVE. This CVE will be updated when the mitigation is available in a Windows security update. We highly encourage customers to subscribe to Security Upda…
Attacker Value
Unknown

CVE-2024-49080

Disclosure Date: December 12, 2024 (last updated February 27, 2025)
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-50387

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Attacker Value
Unknown

CVE-2023-36036

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability