High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 5.5
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
High
CVSS: 7.5
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
High
CVSS: 7.8
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.
High
CVSS: 8.8
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
High
KEV CVSS: 7.8
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Medium
KEV CVSS: 6.2
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
High
KEV CVSS: 7.8
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
High
KEV CVSS: 8.8
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
High
KEV CVSS: 8.8
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
High
CVSS: 7.0
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
High
CVSS: 8.8
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
High
CVSS: 7.0
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.