Critical
CVSS: 9.1
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
Medium
CVSS: 6.5
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
Medium
CVSS: 5.5
Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.