High
CVSS: 8.8
Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
High
CVSS: 8.8
Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
High
CVSS: 7.4
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
High
CVSS: 7.0
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Medium
CVSS: 6.8
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Medium
CVSS: 5.5
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Medium
CVSS: 5.5
Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.
High
KEV CVSS: 7.8
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
High
CVSS: 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
High
CVSS: 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
High
CVSS: 7.8
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
High
CVSS: 7.8
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
High
CVSS: 8.4
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
High
CVSS: 7.8
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
High
CVSS: 7.8
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Medium
CVSS: 5.1
Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.
High
CVSS: 7.0
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.