Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2023-44487
Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1
Attacker Value
Unknown
CVE-2020-1472
Disclosure Date: August 17, 2020 (last updated February 21, 2025)
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network.
To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access.
Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels.
For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020).
When the second phase of Windows updates become available in Q1 2021, customers…
1
Attacker Value
Unknown
CVE-2025-0145
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-54540
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
0
Attacker Value
Unknown
CVE-2024-49105
Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Remote Desktop Client Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-50307
Disclosure Date: October 28, 2024 (last updated October 28, 2024)
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).
0
Attacker Value
Unknown
CVE-2024-39827
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
0
Attacker Value
Unknown
CVE-2024-39821
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access.
0
Attacker Value
Unknown
CVE-2024-39819
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Improper privilege management in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
0
Attacker Value
Unknown
CVE-2024-27240
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.
0