Show filters
2,858 Total Results
Displaying 81-90 of 2,858
Sort by:
Attacker Value
Unknown
CVE-2024-38213
Disclosure Date: August 13, 2024 (last updated August 15, 2024)
Windows Mark of the Web Security Feature Bypass Vulnerability
1
Attacker Value
Unknown
CVE-2024-38193
Disclosure Date: August 13, 2024 (last updated August 15, 2024)
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2024-38202
Disclosure Date: August 08, 2024 (last updated January 12, 2025)
Summary
Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacker attempting to exploit this vulnerability requires additional interaction by a privileged user to be successful.
Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. Note: Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this …
1
Attacker Value
Unknown
CVE-2024-38080
Disclosure Date: July 09, 2024 (last updated January 28, 2025)
Windows Hyper-V Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2023-50387
Disclosure Date: February 14, 2024 (last updated February 21, 2024)
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
1
Attacker Value
Unknown
CVE-2024-21412
Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Internet Shortcut Files Security Feature Bypass Vulnerability
1
Attacker Value
Unknown
CVE-2024-21351
Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Windows SmartScreen Security Feature Bypass Vulnerability
1
Attacker Value
Unknown
CVE-2024-21338
Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Windows Kernel Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2024-20700
Disclosure Date: January 09, 2024 (last updated January 12, 2025)
Windows Hyper-V Remote Code Execution Vulnerability
1
Attacker Value
Unknown
CVE-2024-20654
Disclosure Date: January 09, 2024 (last updated January 12, 2025)
Microsoft ODBC Driver Remote Code Execution Vulnerability
1