High
CVSS: 8.8
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
High
CVSS: 7.0
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.
High
CVSS: 7.8
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 6.7
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.