Medium
CVSS: 6.1
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
High
CVSS: 7.5
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
High
CVSS: 7.8
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Critical
CVSS: 9.9
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
Medium
CVSS: 6.3
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
High
CVSS: 7.3
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.
High
CVSS: 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.0
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 6.5
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
High
CVSS: 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
High
CVSS: 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
Medium
CVSS: 6.5
Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.
High
CVSS: 7.8
Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.