Medium
CVSS: 6.5
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
High
CVSS: 7.5
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
High
CVSS: 7.0
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 6.5
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
High
CVSS: 8.8
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
High
CVSS: 8.8
Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 6.5
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Medium
CVSS: 5.5
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Medium
CVSS: 5.5
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
High
CVSS: 7.8
Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.4
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
High
CVSS: 7.0
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 6.1
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
High
CVSS: 7.4
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Medium
CVSS: 6.1
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
High
CVSS: 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 5.5
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
High
CVSS: 7.8
Use after free in Xbox allows an authorized attacker to elevate privileges locally.