imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2016-0165
Sfruttata Alta 7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_7 · microsoft windows_8.1 · e altri 4
0.14EPSS
CVE-2025-29824
Ransomware Alta 7.8

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.14EPSS
CVE-2024-49039
Ransomware Alta 8.8

Windows Task Scheduler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 9
0.14EPSS
CVE-2024-38213
Sfruttata Media 6.5

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 9
0.14EPSS
CVE-2024-21410
Sfruttata Critica 9.8

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
0.13EPSS
CVE-2023-36424
Sfruttata Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.12EPSS
CVE-2023-21715
Sfruttata Alta 7.3

Microsoft Publisher Security Feature Bypass Vulnerability

microsoft 365_apps
0.12EPSS
CVE-2023-36033
Sfruttata Alta 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · e altri 5
0.12EPSS
CVE-2019-1253
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerab…

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · e altri 4
0.12EPSS
CVE-2021-38648
Sfruttata Alta 7.8

Open Management Infrastructure Elevation of Privilege Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_open_management_infrastructure · e altri 7
0.11EPSS
CVE-2017-0005
Sfruttata Alta 7.8

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 6
0.11EPSS
CVE-2015-2546
Ransomware Alta 8.2

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli…

microsoft windows_10_1507 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.11EPSS
CVE-2023-23376
Ransomware Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.11EPSS
CVE-2022-26925
Sfruttata Alta 8.1

Windows LSA Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.11EPSS
CVE-2021-43890
Ransomware Alta 7.1

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emo…

microsoft app_installer
0.10EPSS
CVE-2021-33771
Sfruttata Alta 7.8

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 10
0.10EPSS
CVE-2023-32046
Sfruttata Alta 7.8

Windows MSHTML Platform Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.10EPSS
CVE-2017-0263
Sfruttata Alta 7.8

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted …

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_10_1703 · e altri 6
0.10EPSS
CVE-2025-21333
Sfruttata Alta 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 3
0.10EPSS
CVE-2024-38217
Sfruttata Media 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.10EPSS
CVE-2022-26904
Sfruttata Alta 7.0

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.10EPSS
CVE-2019-1132
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

microsoft windows_7 · microsoft windows_server_2008
0.10EPSS
CVE-2026-41091
Sfruttata Alta 7.8

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

microsoft malware_protection_engine
0.10EPSS
CVE-2019-0703
Sfruttata Media 6.5

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 11
0.10EPSS
CVE-2021-34486
Sfruttata Alta 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 4
0.09EPSS