Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Very High

CVE-2020-1472 aka Zerologon

Disclosure Date: August 17, 2020 (last updated January 19, 2024)
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers…
Attacker Value
Unknown

CVE-2025-21376

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21375

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-21373

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Installer Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2025-21371

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Telephony Service Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21369

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Microsoft Digest Authentication Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21368

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Microsoft Digest Authentication Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21359

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Kernel Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2025-21352

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Internet Connection Sharing (ICS) Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2025-21350

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Windows Kerberos Denial of Service Vulnerability