imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2026-45659
Ransomware Alta 8.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_server
0.09EPSS
CVE-2010-4398
Sfruttata Alta 7.8

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.09EPSS
CVE-2019-1388
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 10
0.09EPSS
CVE-2021-28310
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · e altri 5
0.08EPSS
CVE-2024-38189
Sfruttata Alta 8.8

Microsoft Project Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office_2019 · microsoft office_long_term_servicing_channel · microsoft project_2016
0.08EPSS
CVE-2021-38646
Ransomware Alta 7.8

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office · microsoft office_2016 · microsoft office_2019
0.08EPSS
CVE-2020-0683
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 13
0.08EPSS
CVE-2019-0676
Sfruttata Media 6.5

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vul…

microsoft internet_explorer
0.08EPSS
CVE-2022-24521
Ransomware Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.07EPSS
CVE-2004-0210
Sfruttata Alta 7.8

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

microsoft interix · microsoft windows_2000 · microsoft windows_nt
0.07EPSS
CVE-2024-38080
Sfruttata Alta 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

microsoft windows_11_21h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_server_2022 · e altri 1
0.07EPSS
CVE-2020-1040
Sfruttata Critica 9.0

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un…

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016
0.07EPSS
CVE-2019-1064
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install pr…

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 7
0.07EPSS
CVE-2026-33825
Ransomware Alta 7.8

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

microsoft defender_antimalware_platform
0.07EPSS
CVE-2021-33739
Sfruttata Alta 8.4

Microsoft DWM Core Library Elevation of Privilege Vulnerability

microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · e altri 2
0.07EPSS
CVE-2025-5419
Sfruttata Alta 8.8

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge_chromium
0.06EPSS
CVE-2026-58644
Sfruttata Critica 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft sharepoint_server
0.06EPSS
CVE-2024-38106
Sfruttata Alta 7.0

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 9
0.06EPSS
CVE-2024-38014
Sfruttata Alta 7.8

Windows Installer Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.06EPSS
CVE-2019-1069
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 7
0.06EPSS
CVE-2025-24990
Sfruttata Alta 7.8

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 12
0.06EPSS
CVE-2025-62215
Sfruttata Alta 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_23h2 · e altri 6
0.06EPSS
CVE-2016-0167
Ransomware Alta 7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_7 · microsoft windows_8.1 · e altri 4
0.06EPSS
CVE-2024-30051
Ransomware Alta 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 7
0.06EPSS
CVE-2023-21823
Sfruttata Alta 7.8

Windows Graphics Component Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.06EPSS