imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2025-32706
Sfruttata Alta 7.8

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.02EPSS
CVE-2021-41357
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · microsoft windows_11_21h2 · e altri 3
0.02EPSS
CVE-2021-40450
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 6
0.02EPSS
CVE-2025-24991
Sfruttata Media 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.02EPSS
CVE-2022-41091
Ransomware Media 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 8
0.02EPSS
CVE-2025-24984
Sfruttata Media 4.6

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.02EPSS
CVE-2019-0797
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 9
0.02EPSS
CVE-2019-1129
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · e altri 4
0.02EPSS
CVE-2025-30400
Sfruttata Alta 7.8

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · e altri 6
0.02EPSS
CVE-2023-28229
Sfruttata Alta 7.0

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.02EPSS
CVE-2025-24989
Sfruttata Alta 8.2

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust…

microsoft power_pages
0.02EPSS
CVE-2022-41033
Sfruttata Alta 7.8

Windows COM+ Event System Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.02EPSS
CVE-2025-32709
Sfruttata Alta 7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.02EPSS
CVE-2024-38107
Sfruttata Alta 7.8

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.02EPSS
CVE-2025-21334
Sfruttata Alta 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 3
0.02EPSS
CVE-2025-21418
Sfruttata Alta 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 10
0.02EPSS
CVE-2026-21514
Sfruttata Alta 7.8

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

microsoft 365_apps · microsoft office_long_term_servicing_channel
0.02EPSS
CVE-2019-1214
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 12
0.01EPSS
CVE-2025-21335
Sfruttata Alta 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · e altri 3
0.01EPSS
CVE-2025-24983
Sfruttata Alta 7.0

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_server_2008 · microsoft windows_server_2012 · e altri 1
0.01EPSS
CVE-2024-49035
Sfruttata Alta 8.7

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

microsoft partner_center
0.01EPSS
CVE-2025-32701
Sfruttata Alta 7.8

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.01EPSS
CVE-2026-68820
Sfruttata Alta 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 9
0.00EPSS
CVE-2023-50387
Alta 7.5

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when ther…

fedoraproject fedora · isc bind · microsoft windows_server_2008 · microsoft windows_server_2012 · e altri 9
1.00EPSS
CVE-2025-53771
Media 6.5

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_server
1.00EPSS