Show filters
837 Total Results
Displaying 11-20 of 837
Sort by:
Attacker Value
Unknown
CVE-2024-43639
Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Windows KDC Proxy Remote Code Execution Vulnerability
2
Attacker Value
Unknown
CVE-2024-38077
Disclosure Date: July 09, 2024 (last updated February 26, 2025)
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
2
Attacker Value
Very Low
CVE-2024-49113
Disclosure Date: December 12, 2024 (last updated February 27, 2025)
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
1
Attacker Value
High
CVE-2024-35250
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
1
Attacker Value
Very Low
CVE-2024-43452
Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Windows Registry Elevation of Privilege Vulnerability
1
Attacker Value
High
CVE-2024-30088
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Kernel Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2024-21302
Disclosure Date: August 08, 2024 (last updated February 26, 2025)
Summary:
Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS.
Microsoft is developing a security update to mitigate this threat, but it is not yet available. Guidance to help customers reduce the risks associated with this vulnerability and to protect their systems until the mitigation is available in a Windows security update is provided in the Recommended Actions section of this CVE.
This CVE will be updated when the mitigation is available in a Windows security update. We highly encourage customers to subscribe to Security Upda…
2
Attacker Value
Unknown
CVE-2024-49080
Disclosure Date: December 12, 2024 (last updated February 27, 2025)
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
1
Attacker Value
Unknown
CVE-2023-50387
Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
1
Attacker Value
Unknown
CVE-2023-36036
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
1