Microsoft Windows Server 2016 20H2

CPE Details

Microsoft Windows Server 2016 20H2
20h2
2021-04-14 12:36 +00:00
2023-05-22 12:36 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:*

Informations

Vendor

microsoft

Product

windows_server_2016

Version

20h2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-38081 2024-07-09 17:03 +00:00 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
7.3
HIGH
CVE-2022-34301 2022-08-25 22:00 +00:00 A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
6.7
MEDIUM
CVE-2022-34302 2022-08-25 22:00 +00:00 A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
6.7
MEDIUM
CVE-2022-34303 2022-08-25 22:00 +00:00 A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
6.7
MEDIUM
CVE-2022-35822 2022-08-15 18:30 +00:00 Windows Defender Credential Guard Security Feature Bypass Vulnerability
7.1
HIGH
CVE-2022-34711 2022-08-15 18:30 +00:00 Windows Defender Credential Guard Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35820 2022-08-09 18:11 +00:00 Windows Bluetooth Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35795 2022-08-09 18:06 +00:00 Windows Error Reporting Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35794 2022-08-09 18:06 +00:00 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-35793 2022-08-09 18:06 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.3
HIGH
CVE-2022-35792 2022-08-09 18:06 +00:00 Storage Spaces Direct Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35771 2022-08-09 17:58 +00:00 Windows Defender Credential Guard Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35769 2022-08-09 17:58 +00:00 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
7.5
HIGH
CVE-2022-35768 2022-08-09 17:57 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35767 2022-08-09 17:57 +00:00 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-35766 2022-08-09 17:57 +00:00 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-35765 2022-08-09 17:57 +00:00 Storage Spaces Direct Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35764 2022-08-09 17:57 +00:00 Storage Spaces Direct Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35763 2022-08-09 17:56 +00:00 Storage Spaces Direct Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35762 2022-08-09 17:56 +00:00 Storage Spaces Direct Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35761 2022-08-09 17:56 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-35760 2022-08-09 17:56 +00:00 Microsoft ATA Port Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-34714 2022-08-09 17:55 +00:00 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-34712 2022-08-09 17:54 +00:00 Windows Defender Credential Guard Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-34710 2022-08-09 17:54 +00:00 Windows Defender Credential Guard Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-34709 2022-08-09 17:54 +00:00 Windows Defender Credential Guard Security Feature Bypass Vulnerability
6
MEDIUM
CVE-2022-34708 2022-08-09 17:54 +00:00 Windows Kernel Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-34707 2022-08-09 17:54 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-34706 2022-08-09 17:53 +00:00 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-34705 2022-08-09 17:53 +00:00 Windows Defender Credential Guard Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-34703 2022-08-09 17:53 +00:00 Windows Partition Management Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-34702 2022-08-09 17:52 +00:00 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-34701 2022-08-09 17:52 +00:00 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
7.5
HIGH
CVE-2022-34699 2022-08-09 17:52 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-34696 2022-08-09 17:52 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-34691 2022-08-09 17:51 +00:00 Active Directory Domain Services Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2022-34690 2022-08-09 17:51 +00:00 Windows Fax Service Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2022-33670 2022-08-09 17:50 +00:00 Windows Partition Management Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-30197 2022-08-09 17:49 +00:00 Windows Kernel Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-30194 2022-08-09 17:49 +00:00 Windows WebBrowser Control Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-30133 2022-08-09 17:48 +00:00 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2022-34704 2022-08-08 22:00 +00:00 Windows Defender Credential Guard Information Disclosure Vulnerability
4.7
MEDIUM
CVE-2022-30226 2022-07-12 20:37 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2022-30225 2022-07-12 20:37 +00:00 Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2022-30224 2022-07-12 20:37 +00:00 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-30223 2022-07-12 20:37 +00:00 Windows Hyper-V Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2022-30222 2022-07-12 20:37 +00:00 Windows Shell Remote Code Execution Vulnerability
8.4
HIGH
CVE-2022-30221 2022-07-12 20:37 +00:00 Windows Graphics Component Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-30220 2022-07-12 20:37 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-30216 2022-07-12 20:37 +00:00 Windows Server Service Tampering Vulnerability
8.8
HIGH
CVE-2022-30215 2022-07-12 20:37 +00:00 Active Directory Federation Services Elevation of Privilege Vulnerability
7.5
HIGH
CVE-2022-30214 2022-07-12 20:37 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-30213 2022-07-12 20:37 +00:00 Windows GDI+ Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-30212 2022-07-12 20:37 +00:00 Windows Connected Devices Platform Service Information Disclosure Vulnerability
4.7
MEDIUM
CVE-2022-30211 2022-07-12 20:37 +00:00 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-30209 2022-07-12 20:37 +00:00 Windows IIS Server Elevation of Privilege Vulnerability
7.4
HIGH
CVE-2022-30208 2022-07-12 20:37 +00:00 Windows Security Account Manager (SAM) Denial of Service Vulnerability
6.5
MEDIUM
CVE-2022-30206 2022-07-12 20:37 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-30205 2022-07-12 20:37 +00:00 Windows Group Policy Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2022-30203 2022-07-12 20:37 +00:00 Windows Boot Manager Security Feature Bypass Vulnerability
7.4
HIGH
CVE-2022-30202 2022-07-12 20:37 +00:00 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-22711 2022-07-12 20:37 +00:00 Windows BitLocker Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2022-22050 2022-07-12 20:37 +00:00 Windows Fax Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-22049 2022-07-12 20:37 +00:00 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-22048 2022-07-12 20:37 +00:00 BitLocker Security Feature Bypass Vulnerability
6.1
MEDIUM
CVE-2022-22045 2022-07-12 20:37 +00:00 Windows.Devices.Picker.dll Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-22043 2022-07-12 20:37 +00:00 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-22042 2022-07-12 20:37 +00:00 Windows Hyper-V Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-22041 2022-07-12 20:37 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
6.8
MEDIUM
CVE-2022-22040 2022-07-12 20:37 +00:00 Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
7.3
HIGH
CVE-2022-22039 2022-07-12 20:37 +00:00 Windows Network File System Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-22038 2022-07-12 20:37 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-22037 2022-07-12 20:37 +00:00 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
7.5
HIGH
CVE-2022-22036 2022-07-12 20:37 +00:00 Performance Counters for Windows Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-22034 2022-07-12 20:37 +00:00 Windows Graphics Component Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-22031 2022-07-12 20:36 +00:00 Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-22029 2022-07-12 20:36 +00:00 Windows Network File System Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-22028 2022-07-12 20:36 +00:00 Windows Network File System Information Disclosure Vulnerability
5.9
MEDIUM
CVE-2022-22027 2022-07-12 20:36 +00:00 Windows Fax Service Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-22026 2022-07-12 20:36 +00:00 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2022-30166 2022-06-15 19:52 +00:00 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-30165 2022-06-15 19:52 +00:00 Windows Kerberos Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2022-30164 2022-06-15 19:51 +00:00 Kerberos AppContainer Security Feature Bypass Vulnerability
7.8
HIGH
CVE-2022-30163 2022-06-15 19:51 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
8.5
HIGH
CVE-2022-30162 2022-06-15 19:51 +00:00 Windows Kernel Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-30161 2022-06-15 19:51 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-30160 2022-06-15 19:51 +00:00 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-30155 2022-06-15 19:51 +00:00 Windows Kernel Denial of Service Vulnerability
5.5
MEDIUM
CVE-2022-30153 2022-06-15 19:51 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-30152 2022-06-15 19:51 +00:00 Windows Network Address Translation (NAT) Denial of Service Vulnerability
7.5
HIGH
CVE-2022-30151 2022-06-15 19:51 +00:00 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-30149 2022-06-15 19:51 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-30146 2022-06-15 19:51 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-30143 2022-06-15 19:51 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-30141 2022-06-15 19:51 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-30140 2022-06-15 19:51 +00:00 Windows iSCSI Discovery Service Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-30131 2022-06-15 19:51 +00:00 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-30138 2022-05-18 21:10 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26934 2022-05-10 18:33 +00:00 Windows Graphics Component Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-26920 2022-04-15 17:05 +00:00 Windows Graphics Component Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-26919 2022-04-15 17:05 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-26918 2022-04-15 17:05 +00:00 Windows Fax Compose Form Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-26917 2022-04-15 17:05 +00:00 Windows Fax Compose Form Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-26916 2022-04-15 17:05 +00:00 Windows Fax Compose Form Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-26915 2022-04-15 17:05 +00:00 Windows Secure Channel Denial of Service Vulnerability
7.5
HIGH
CVE-2022-26914 2022-04-15 17:05 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26903 2022-04-15 17:05 +00:00 Windows Graphics Component Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-26832 2022-04-15 17:05 +00:00 .NET Framework Denial of Service Vulnerability
7.5
HIGH
CVE-2022-26831 2022-04-15 17:05 +00:00 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
7.5
HIGH
CVE-2022-26829 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26828 2022-04-15 17:05 +00:00 Windows Bluetooth Driver Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-26827 2022-04-15 17:05 +00:00 Windows File Server Resource Management Service Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-26826 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26825 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26824 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26823 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26822 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26821 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26820 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26819 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26818 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26817 2022-04-15 17:05 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26816 2022-04-15 17:05 +00:00 Windows DNS Server Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-26815 2022-04-15 17:04 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26814 2022-04-15 17:04 +00:00 Windows DNS Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2022-26813 2022-04-15 17:04 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26812 2022-04-15 17:04 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26811 2022-04-15 17:04 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-26810 2022-04-15 17:04 +00:00 Windows File Server Resource Management Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26809 2022-04-15 17:04 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2022-26808 2022-04-15 17:04 +00:00 Windows File Explorer Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-26807 2022-04-15 17:04 +00:00 Windows Work Folder Service Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-26803 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26802 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26801 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26798 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26797 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26796 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26795 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26794 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26793 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26792 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26791 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26790 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26789 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26788 2022-04-15 17:04 +00:00 PowerShell Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26787 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26786 2022-04-15 17:04 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-26785 2022-04-15 17:04 +00:00 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-26784 2022-04-15 17:04 +00:00 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability
6.5
MEDIUM
CVE-2022-26783 2022-04-15 17:04 +00:00 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-24550 2022-04-15 17:04 +00:00 Windows Telephony Server Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24549 2022-04-15 17:04 +00:00 Windows AppX Package Manager Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24547 2022-04-15 17:04 +00:00 Windows Digital Media Receiver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24546 2022-04-15 17:04 +00:00 Windows DWM Core Library Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24545 2022-04-15 17:04 +00:00 Windows Kerberos Remote Code Execution Vulnerability
8.1
HIGH
CVE-2022-24544 2022-04-15 17:04 +00:00 Windows Kerberos Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24542 2022-04-15 17:04 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24541 2022-04-15 17:04 +00:00 Windows Server Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-24540 2022-04-15 17:03 +00:00 Windows ALPC Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-24539 2022-04-15 17:03 +00:00 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
8.1
HIGH
CVE-2022-24538 2022-04-15 17:03 +00:00 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability
6.5
MEDIUM
CVE-2022-24536 2022-04-15 17:03 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2022-24534 2022-04-15 17:03 +00:00 Win32 Stream Enumeration Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-24533 2022-04-15 17:03 +00:00 Remote Desktop Protocol Remote Code Execution Vulnerability
8
HIGH
CVE-2022-24530 2022-04-15 17:03 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24528 2022-04-15 17:03 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-24500 2022-04-15 17:03 +00:00 Windows SMB Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-24499 2022-04-15 17:03 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24498 2022-04-15 17:03 +00:00 Windows iSCSI Target Service Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-24497 2022-04-15 17:03 +00:00 Windows Network File System Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2022-24496 2022-04-15 17:03 +00:00 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24495 2022-04-15 17:03 +00:00 Windows Direct Show - Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-24494 2022-04-15 17:03 +00:00 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24493 2022-04-15 17:03 +00:00 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-24492 2022-04-15 17:03 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-24491 2022-04-15 17:03 +00:00 Windows Network File System Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2022-24490 2022-04-15 17:03 +00:00 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
8.1
HIGH
CVE-2022-24489 2022-04-15 17:03 +00:00 Cluster Client Failover (CCF) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24488 2022-04-15 17:03 +00:00 Windows Desktop Bridge Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24487 2022-04-15 17:03 +00:00 Windows Local Security Authority (LSA) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-24486 2022-04-15 17:03 +00:00 Windows Kerberos Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24485 2022-04-15 17:03 +00:00 Win32 File Enumeration Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-24484 2022-04-15 17:03 +00:00 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability
5.5
MEDIUM
CVE-2022-24483 2022-04-15 17:03 +00:00 Windows Kernel Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-24482 2022-04-15 17:03 +00:00 Windows ALPC Elevation of Privilege Vulnerability
7
HIGH
CVE-2022-24481 2022-04-15 17:03 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24479 2022-04-15 17:03 +00:00 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-24474 2022-04-15 17:03 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-23257 2022-04-15 17:02 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-22009 2022-04-15 17:02 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-22008 2022-04-15 17:02 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-21983 2022-04-15 17:02 +00:00 Win32 Stream Enumeration Remote Code Execution Vulnerability
7.5
HIGH
CVE-2022-21871 2022-01-11 19:22 +00:00 Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-42288 2021-11-09 23:47 +00:00 Windows Hello Security Feature Bypass Vulnerability
6.1
MEDIUM
CVE-2021-42280 2021-11-09 23:47 +00:00 Windows Feedback Hub Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-42279 2021-11-09 23:47 +00:00 Chakra Scripting Engine Memory Corruption Vulnerability
7.5
HIGH
CVE-2021-42277 2021-11-09 23:47 +00:00 Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-42276 2021-11-09 23:47 +00:00 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-42275 2021-11-09 23:46 +00:00 Microsoft COM for Windows Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-42274 2021-11-09 23:46 +00:00 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
6.8
MEDIUM
CVE-2021-41378 2021-11-09 23:46 +00:00 Windows NTFS Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-41377 2021-11-09 23:46 +00:00 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41371 2021-11-09 23:46 +00:00 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
4.4
MEDIUM
CVE-2021-41370 2021-11-09 23:46 +00:00 NTFS Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41367 2021-11-09 23:46 +00:00 NTFS Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41366 2021-11-09 23:46 +00:00 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41356 2021-11-09 23:46 +00:00 Windows Denial of Service Vulnerability
7.5
HIGH
CVE-2021-38666 2021-11-09 23:46 +00:00 Remote Desktop Client Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-38631 2021-11-09 23:46 +00:00 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
4.4
MEDIUM
CVE-2021-36957 2021-11-09 23:46 +00:00 Windows Desktop Bridge Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26443 2021-11-09 23:46 +00:00 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
9
CRITICAL
CVE-2021-41361 2021-10-12 22:28 +00:00 Active Directory Federation Server Spoofing Vulnerability
5.4
MEDIUM
CVE-2021-41347 2021-10-12 22:28 +00:00 Windows AppX Deployment Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41346 2021-10-12 22:28 +00:00 Console Window Host Security Feature Bypass Vulnerability
7.8
HIGH
CVE-2021-41345 2021-10-12 22:28 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41343 2021-10-12 22:28 +00:00 Windows Fast FAT File System Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-41340 2021-10-12 22:27 +00:00 Windows Graphics Component Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-41339 2021-10-12 22:27 +00:00 Microsoft DWM Core Library Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41338 2021-10-12 22:27 +00:00 Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
5.5
MEDIUM
CVE-2021-41337 2021-10-12 22:27 +00:00 Active Directory Security Feature Bypass Vulnerability
4.9
MEDIUM
CVE-2021-41335 2021-10-12 22:27 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41334 2021-10-12 22:27 +00:00 Windows Desktop Bridge Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-41332 2021-10-12 22:27 +00:00 Windows Print Spooler Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-41331 2021-10-12 22:27 +00:00 Windows Media Audio Decoder Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-41330 2021-10-12 22:27 +00:00 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-40489 2021-10-12 22:27 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40488 2021-10-12 22:27 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40478 2021-10-12 22:27 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40477 2021-10-12 22:27 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40476 2021-10-12 22:27 +00:00 Windows AppContainer Elevation Of Privilege Vulnerability
7.8
HIGH
CVE-2021-40475 2021-10-12 22:27 +00:00 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-40470 2021-10-12 22:27 +00:00 DirectX Graphics Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40469 2021-10-12 22:27 +00:00 Windows DNS Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2021-40468 2021-10-12 22:27 +00:00 Windows Bind Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-40467 2021-10-12 22:27 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40466 2021-10-12 22:27 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40463 2021-10-12 22:27 +00:00 Windows Network Address Translation (NAT) Denial of Service Vulnerability
7.7
HIGH
CVE-2021-26442 2021-10-12 22:26 +00:00 Windows HTTP.sys Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-40447 2021-09-15 09:24 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38671 2021-09-15 09:24 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38667 2021-09-15 09:24 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38639 2021-09-15 09:24 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38637 2021-09-15 09:23 +00:00 Windows Storage Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-38638 2021-09-15 09:23 +00:00 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38636 2021-09-15 09:23 +00:00 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-38635 2021-09-15 09:23 +00:00 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-38634 2021-09-15 09:23 +00:00 Microsoft Windows Update Client Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38633 2021-09-15 09:23 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38632 2021-09-15 09:23 +00:00 BitLocker Security Feature Bypass Vulnerability
5.7
MEDIUM
CVE-2021-38630 2021-09-15 09:23 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38629 2021-09-15 09:23 +00:00 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-38628 2021-09-15 09:23 +00:00 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-38624 2021-09-15 09:23 +00:00 Windows Key Storage Provider Security Feature Bypass Vulnerability
6.5
MEDIUM
CVE-2021-36975 2021-09-15 09:23 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-36974 2021-09-15 09:23 +00:00 Windows SMB Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-36973 2021-09-15 09:23 +00:00 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-36972 2021-09-15 09:23 +00:00 Windows SMB Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-36969 2021-09-15 09:23 +00:00 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-36966 2021-09-15 09:23 +00:00 Windows Subsystem for Linux Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-36967 2021-09-15 09:23 +00:00 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-36965 2021-09-15 09:23 +00:00 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-36964 2021-09-15 09:23 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-36963 2021-09-15 09:23 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-36962 2021-09-15 09:23 +00:00 Windows Installer Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-36961 2021-09-15 09:23 +00:00 Windows Installer Denial of Service Vulnerability
6.1
MEDIUM
CVE-2021-36960 2021-09-15 09:23 +00:00 Windows SMB Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-36959 2021-09-15 09:23 +00:00 Windows Authenticode Spoofing Vulnerability
5.5
MEDIUM
CVE-2021-36954 2021-09-15 09:23 +00:00 Windows Bind Filter Driver Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-26435 2021-09-15 09:23 +00:00 Windows Scripting Engine Memory Corruption Vulnerability
8.1
HIGH
CVE-2021-36947 2021-08-12 16:12 +00:00 Windows Print Spooler Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-36937 2021-08-12 16:12 +00:00 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-36936 2021-08-12 16:12 +00:00 Windows Print Spooler Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-36933 2021-08-12 16:12 +00:00 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-36932 2021-08-12 16:12 +00:00 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-36926 2021-08-12 16:12 +00:00 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-34537 2021-08-12 16:12 +00:00 Windows Bluetooth Driver Elevation of Privilege Vulnerability
8
HIGH
CVE-2021-34536 2021-08-12 16:12 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34533 2021-08-12 16:12 +00:00 Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34530 2021-08-12 16:12 +00:00 Windows Graphics Component Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34487 2021-08-12 16:12 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34483 2021-08-12 16:11 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26433 2021-08-12 16:11 +00:00 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-26432 2021-08-12 16:11 +00:00 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-26431 2021-08-12 16:11 +00:00 Windows Recovery Environment Agent Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26426 2021-08-12 16:11 +00:00 Windows User Account Profile Picture Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26425 2021-08-12 16:11 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26424 2021-08-12 16:11 +00:00 Windows TCP/IP Remote Code Execution Vulnerability
9.9
CRITICAL
CVE-2021-34462 2021-07-16 18:19 +00:00 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34461 2021-07-16 18:19 +00:00 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34460 2021-07-16 18:19 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34459 2021-07-16 18:19 +00:00 Windows AppContainer Elevation Of Privilege Vulnerability
7.8
HIGH
CVE-2021-34458 2021-07-16 18:19 +00:00 Windows Kernel Remote Code Execution Vulnerability
9.9
CRITICAL
CVE-2021-34457 2021-07-16 18:19 +00:00 Windows Remote Access Connection Manager Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34456 2021-07-16 18:19 +00:00 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34454 2021-07-16 18:19 +00:00 Windows Remote Access Connection Manager Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34455 2021-07-16 18:19 +00:00 Windows File History Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34450 2021-07-16 18:19 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
9.9
CRITICAL
CVE-2021-34449 2021-07-16 18:19 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34445 2021-07-16 18:19 +00:00 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34444 2021-07-16 18:19 +00:00 Windows DNS Server Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-34441 2021-07-16 18:19 +00:00 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34442 2021-07-16 18:19 +00:00 Windows DNS Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-34440 2021-07-16 18:19 +00:00 GDI+ Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34438 2021-07-16 18:19 +00:00 Windows Font Driver Host Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34525 2021-07-14 15:54 +00:00 Windows DNS Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-34521 2021-07-14 15:54 +00:00 Raw Image Extension Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34516 2021-07-14 15:54 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34514 2021-07-14 15:54 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34513 2021-07-14 15:54 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34512 2021-07-14 15:54 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34511 2021-07-14 15:54 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34510 2021-07-14 15:54 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34509 2021-07-14 15:54 +00:00 Storage Spaces Controller Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34508 2021-07-14 15:54 +00:00 Windows Kernel Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-34507 2021-07-14 15:54 +00:00 Windows Remote Assistance Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-34504 2021-07-14 15:54 +00:00 Windows Address Book Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34500 2021-07-14 15:54 +00:00 Windows Kernel Memory Information Disclosure Vulnerability
7.7
HIGH
CVE-2021-34499 2021-07-14 15:54 +00:00 Windows DNS Server Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-34498 2021-07-14 15:54 +00:00 Windows GDI Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34497 2021-07-14 15:54 +00:00 Windows MSHTML Platform Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-34496 2021-07-14 15:54 +00:00 Windows GDI Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34494 2021-07-14 15:54 +00:00 Windows DNS Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-34493 2021-07-14 15:54 +00:00 Windows Partition Management Driver Elevation of Privilege Vulnerability
6.7
MEDIUM
CVE-2021-34492 2021-07-14 15:54 +00:00 Windows Certificate Spoofing Vulnerability
8.1
HIGH
CVE-2021-34491 2021-07-14 15:54 +00:00 Win32k Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-34490 2021-07-14 15:54 +00:00 Windows TCP/IP Driver Denial of Service Vulnerability
7.5
HIGH
CVE-2021-34489 2021-07-14 15:54 +00:00 DirectWrite Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-34488 2021-07-14 15:54 +00:00 Windows Console Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-34476 2021-07-14 15:54 +00:00 Bowser.sys Denial of Service Vulnerability
7.5
HIGH
CVE-2021-33788 2021-07-14 15:53 +00:00 Windows LSA Denial of Service Vulnerability
7.5
HIGH
CVE-2021-33786 2021-07-14 15:53 +00:00 Windows LSA Security Feature Bypass Vulnerability
8.8
HIGH
CVE-2021-33785 2021-07-14 15:53 +00:00 Windows AF_UNIX Socket Provider Denial of Service Vulnerability
7.5
HIGH
CVE-2021-33784 2021-07-14 15:53 +00:00 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-33783 2021-07-14 15:53 +00:00 Windows SMB Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-33782 2021-07-14 15:53 +00:00 Windows Authenticode Spoofing Vulnerability
5.5
MEDIUM
CVE-2021-33781 2021-07-14 15:53 +00:00 Azure AD Security Feature Bypass Vulnerability
8.1
HIGH
CVE-2021-33780 2021-07-14 15:53 +00:00 Windows DNS Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-33779 2021-07-14 15:53 +00:00 Windows AD FS Security Feature Bypass Vulnerability
8.1
HIGH
CVE-2021-33774 2021-07-14 15:53 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-33773 2021-07-14 15:53 +00:00 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-33772 2021-07-14 15:53 +00:00 Windows TCP/IP Driver Denial of Service Vulnerability
7.5
HIGH
CVE-2021-33765 2021-07-14 15:53 +00:00 Windows Installer Spoofing Vulnerability
6.2
MEDIUM
CVE-2021-33764 2021-07-14 15:53 +00:00 Windows Key Distribution Center Information Disclosure Vulnerability
5.9
MEDIUM
CVE-2021-33763 2021-07-14 15:53 +00:00 Windows Remote Access Connection Manager Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-33761 2021-07-14 15:53 +00:00 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-33759 2021-07-14 15:53 +00:00 Windows Desktop Bridge Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-33757 2021-07-14 15:53 +00:00 Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
9.8
CRITICAL
CVE-2021-33756 2021-07-14 15:53 +00:00 Windows DNS Snap-in Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-33755 2021-07-14 15:53 +00:00 Windows Hyper-V Denial of Service Vulnerability
8.6
HIGH
CVE-2021-33754 2021-07-14 15:53 +00:00 Windows DNS Server Remote Code Execution Vulnerability
8
HIGH
CVE-2021-33752 2021-07-14 15:53 +00:00 Windows DNS Snap-in Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-33751 2021-07-14 15:53 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-33750 2021-07-14 15:53 +00:00 Windows DNS Snap-in Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-33749 2021-07-14 15:53 +00:00 Windows DNS Snap-in Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-33746 2021-07-14 15:53 +00:00 Windows DNS Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-33745 2021-07-14 15:53 +00:00 Windows DNS Server Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-33744 2021-07-14 15:53 +00:00 Windows Secure Kernel Mode Security Feature Bypass Vulnerability
6.7
MEDIUM
CVE-2021-33743 2021-07-14 15:53 +00:00 Windows Projected File System Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31961 2021-07-14 15:53 +00:00 Windows InstallService Elevation of Privilege Vulnerability
6.1
MEDIUM
CVE-2021-31183 2021-07-14 15:53 +00:00 Windows TCP/IP Driver Denial of Service Vulnerability
7.5
HIGH
CVE-2021-31976 2021-06-08 20:46 +00:00 Server for NFS Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-31977 2021-06-08 20:46 +00:00 Windows Hyper-V Denial of Service Vulnerability
8.6
HIGH
CVE-2021-31975 2021-06-08 20:46 +00:00 Server for NFS Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-31973 2021-06-08 20:46 +00:00 Windows GPSVC Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31974 2021-06-08 20:46 +00:00 Server for NFS Denial of Service Vulnerability
7.5
HIGH
CVE-2021-31972 2021-06-08 20:46 +00:00 Event Tracing for Windows Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-31969 2021-06-08 20:46 +00:00 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31970 2021-06-08 20:46 +00:00 Windows TCP/IP Driver Security Feature Bypass Vulnerability
5.5
MEDIUM
CVE-2021-31968 2021-06-08 20:46 +00:00 Windows Remote Desktop Services Denial of Service Vulnerability
7.5
HIGH
CVE-2021-31962 2021-06-08 20:46 +00:00 Kerberos AppContainer Security Feature Bypass Vulnerability
9.8
CRITICAL
CVE-2021-31960 2021-06-08 20:46 +00:00 Windows Bind Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-31958 2021-06-08 20:46 +00:00 Windows NTLM Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-31954 2021-06-08 20:46 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31952 2021-06-08 20:46 +00:00 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31951 2021-06-08 20:46 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31208 2021-05-11 17:11 +00:00 Windows Container Manager Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31205 2021-05-11 17:11 +00:00 Windows SMB Client Security Feature Bypass Vulnerability
6.5
MEDIUM
CVE-2021-31194 2021-05-11 17:11 +00:00 OLE Automation Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-31193 2021-05-11 17:11 +00:00 Windows SSDP Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31191 2021-05-11 17:11 +00:00 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-31188 2021-05-11 17:11 +00:00 Windows Graphics Component Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31185 2021-05-11 17:11 +00:00 Windows Desktop Bridge Denial of Service Vulnerability
5.5
MEDIUM
CVE-2021-31186 2021-05-11 17:11 +00:00 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
7.4
HIGH
CVE-2021-31184 2021-05-11 17:11 +00:00 Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-31182 2021-05-11 17:11 +00:00 Microsoft Bluetooth Driver Spoofing Vulnerability
7.1
HIGH
CVE-2021-31169 2021-05-11 17:11 +00:00 Windows Container Manager Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31170 2021-05-11 17:11 +00:00 Windows Graphics Component Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31168 2021-05-11 17:11 +00:00 Windows Container Manager Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31167 2021-05-11 17:11 +00:00 Windows Container Manager Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-31165 2021-05-11 17:11 +00:00 Windows Container Manager Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28479 2021-05-11 17:11 +00:00 Windows CSC Service Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-28476 2021-05-11 17:11 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
9.9
CRITICAL
CVE-2021-28455 2021-05-11 17:11 +00:00 Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28447 2021-04-13 17:33 +00:00 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
4.4
MEDIUM
CVE-2021-28446 2021-04-13 17:33 +00:00 Windows Portmapping Information Disclosure Vulnerability
7.1
HIGH
CVE-2021-28444 2021-04-13 17:33 +00:00 Windows Hyper-V Security Feature Bypass Vulnerability
6.5
MEDIUM
CVE-2021-28445 2021-04-13 17:33 +00:00 Windows Network File System Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28443 2021-04-13 17:33 +00:00 Windows Console Driver Denial of Service Vulnerability
5.5
MEDIUM
CVE-2021-28441 2021-04-13 17:33 +00:00 Windows Hyper-V Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-28442 2021-04-13 17:33 +00:00 Windows TCP/IP Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-28440 2021-04-13 17:33 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28438 2021-04-13 17:33 +00:00 Windows Console Driver Denial of Service Vulnerability
5.5
MEDIUM
CVE-2021-28439 2021-04-13 17:33 +00:00 Windows TCP/IP Driver Denial of Service Vulnerability
7.5
HIGH
CVE-2021-28437 2021-04-13 17:33 +00:00 Windows Installer Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-28435 2021-04-13 17:33 +00:00 Windows Event Tracing Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-28436 2021-04-13 17:33 +00:00 Windows Speech Runtime Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28434 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28357 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28358 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28356 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28354 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28355 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28353 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28351 2021-04-13 17:33 +00:00 Windows Speech Runtime Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28352 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28350 2021-04-13 17:33 +00:00 Windows GDI+ Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-28349 2021-04-13 17:33 +00:00 Windows GDI+ Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-28347 2021-04-13 17:33 +00:00 Windows Speech Runtime Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28348 2021-04-13 17:33 +00:00 Windows GDI+ Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-28346 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28344 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28345 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28343 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28341 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28342 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28340 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28338 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28339 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28337 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28336 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28334 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28335 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28333 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28332 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28330 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28331 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28329 2021-04-13 17:33 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28328 2021-04-13 17:33 +00:00 Windows DNS Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-28326 2021-04-13 17:32 +00:00 Windows AppX Deployment Server Denial of Service Vulnerability
6.1
MEDIUM
CVE-2021-28327 2021-04-13 17:32 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28325 2021-04-13 17:32 +00:00 Windows SMB Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-28324 2021-04-13 17:32 +00:00 Windows SMB Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-28322 2021-04-13 17:32 +00:00 Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28323 2021-04-13 17:32 +00:00 Windows DNS Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2021-28321 2021-04-13 17:32 +00:00 Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28319 2021-04-13 17:32 +00:00 Windows TCP/IP Driver Denial of Service Vulnerability
7.5
HIGH
CVE-2021-28320 2021-04-13 17:32 +00:00 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28318 2021-04-13 17:32 +00:00 Windows GDI+ Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-28317 2021-04-13 17:32 +00:00 Microsoft Windows Codecs Library Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-28315 2021-04-13 17:32 +00:00 Windows Media Video Decoder Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-28316 2021-04-13 17:32 +00:00 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
4.6
MEDIUM
CVE-2021-28314 2021-04-13 17:32 +00:00 Windows Hyper-V Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28312 2021-04-13 17:32 +00:00 Windows NTFS Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-28313 2021-04-13 17:32 +00:00 Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28311 2021-04-13 17:32 +00:00 Windows Application Compatibility Cache Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-27096 2021-04-13 17:32 +00:00 NTFS Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-28309 2021-04-13 17:32 +00:00 Windows Kernel Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-27095 2021-04-13 17:32 +00:00 Windows Media Video Decoder Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-27094 2021-04-13 17:32 +00:00 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
4.4
MEDIUM
CVE-2021-27093 2021-04-13 17:32 +00:00 Windows Kernel Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-27092 2021-04-13 17:32 +00:00 Azure AD Web Sign-in Security Feature Bypass Vulnerability
9.8
CRITICAL
CVE-2021-27090 2021-04-13 17:32 +00:00 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-27088 2021-04-13 17:32 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-27089 2021-04-13 17:32 +00:00 Microsoft Internet Messaging API Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-27086 2021-04-13 17:32 +00:00 Windows Services and Controller App Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-27079 2021-04-13 17:32 +00:00 Windows Media Photo Codec Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2021-27072 2021-04-13 17:32 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26417 2021-04-13 17:32 +00:00 Windows Overlay Filter Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-26415 2021-04-13 17:32 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26416 2021-04-13 17:32 +00:00 Windows Hyper-V Denial of Service Vulnerability
7.7
HIGH
CVE-2021-26413 2021-04-13 17:32 +00:00 Windows Installer Spoofing Vulnerability
6.2
MEDIUM
CVE-2021-27077 2021-03-11 14:50 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-27070 2021-03-11 14:49 +00:00 Windows 10 Update Assistant Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-27063 2021-03-11 14:49 +00:00 Windows DNS Server Denial of Service Vulnerability
7.5
HIGH
CVE-2021-26901 2021-03-11 14:44 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26900 2021-03-11 14:44 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26899 2021-03-11 14:43 +00:00 Windows UPnP Device Host Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26898 2021-03-11 14:43 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26897 2021-03-11 14:43 +00:00 Windows DNS Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-26896 2021-03-11 14:43 +00:00 Windows DNS Server Denial of Service Vulnerability
7.5
HIGH
CVE-2021-26895 2021-03-11 14:43 +00:00 Windows DNS Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-26894 2021-03-11 14:43 +00:00 Windows DNS Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-26893 2021-03-11 14:42 +00:00 Windows DNS Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-26892 2021-03-11 14:42 +00:00 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
6.2
MEDIUM
CVE-2021-26891 2021-03-11 14:42 +00:00 Windows Container Execution Agent Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26890 2021-03-11 14:42 +00:00 Application Virtualization Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-26889 2021-03-11 14:42 +00:00 Windows Update Stack Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26887 2021-03-11 14:42 +00:00

An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability would be able to begin redirecting another user's personal data to a created folder.

To exploit the vulnerability, an attacker can create a new folder under the Folder Redirection root path and create a junction on a newly created User folder. When the new user logs in, Folder Redirection would start redirecting to the folder and copying personal data.

This elevation of privilege vulnerability can only be addressed by reconfiguring Folder Redirection with Offline files and restricting permissions, and NOT via a security update for affected Windows Servers. See the FAQ section of this CVE for configuration guidance.

7.8
HIGH
CVE-2021-26886 2021-03-11 14:42 +00:00 User Profile Service Denial of Service Vulnerability
6.1
MEDIUM
CVE-2021-26884 2021-03-11 14:41 +00:00 Windows Media Photo Codec Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-26882 2021-03-11 14:41 +00:00 Remote Access API Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26881 2021-03-11 14:41 +00:00 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-26880 2021-03-11 14:41 +00:00 Storage Spaces Controller Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26879 2021-03-11 14:41 +00:00 Windows Network Address Translation (NAT) Denial of Service Vulnerability
7.5
HIGH
CVE-2021-26878 2021-03-11 14:40 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26877 2021-03-11 14:40 +00:00 Windows DNS Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-26876 2021-03-11 14:39 +00:00 OpenType Font Parsing Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-26874 2021-03-11 14:39 +00:00 Windows Overlay Filter Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26873 2021-03-11 14:39 +00:00 Windows User Profile Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26872 2021-03-11 14:39 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26870 2021-03-11 14:39 +00:00 Windows Projected File System Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26869 2021-03-11 14:39 +00:00 Windows ActiveX Installer Service Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-26868 2021-03-11 14:38 +00:00 Windows Graphics Component Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26867 2021-03-11 14:38 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
9.9
CRITICAL
CVE-2021-26866 2021-03-11 14:38 +00:00 Windows Update Service Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2021-26865 2021-03-11 14:38 +00:00 Windows Container Execution Agent Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-26864 2021-03-11 14:37 +00:00 Windows Virtual Registry Provider Elevation of Privilege Vulnerability
8.4
HIGH
CVE-2021-26863 2021-03-11 14:37 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26862 2021-03-11 14:37 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-26861 2021-03-11 14:37 +00:00 Windows Graphics Component Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-26860 2021-03-11 14:36 +00:00 Windows App-V Overlay Filter Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24107 2021-03-11 14:03 +00:00 Windows Event Tracing Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-24095 2021-03-11 14:02 +00:00 DirectX Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24090 2021-03-11 14:01 +00:00 Windows Error Reporting Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1729 2021-03-11 13:58 +00:00 Windows Update Stack Setup Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1640 2021-03-10 15:27 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-25195 2021-02-25 22:01 +00:00 Windows PKU2U Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24111 2021-02-25 22:01 +00:00 .NET Framework Denial of Service Vulnerability
7.5
HIGH
CVE-2021-24106 2021-02-25 22:01 +00:00 Windows DirectX Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-24103 2021-02-25 22:01 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24102 2021-02-25 22:01 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24098 2021-02-25 22:01 +00:00 Windows Console Driver Denial of Service Vulnerability
5.5
MEDIUM
CVE-2021-24094 2021-02-25 22:01 +00:00 Windows TCP/IP Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-24096 2021-02-25 22:01 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24093 2021-02-25 22:01 +00:00 Windows Graphics Component Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-24092 2021-02-25 22:01 +00:00 Microsoft Defender Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-24088 2021-02-25 22:01 +00:00 Windows Local Spooler Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-24091 2021-02-25 22:01 +00:00 Windows Camera Codec Pack Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-24086 2021-02-25 22:01 +00:00 Windows TCP/IP Denial of Service Vulnerability
7.5
HIGH
CVE-2021-24083 2021-02-25 22:01 +00:00 Windows Address Book Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-24084 2021-02-25 22:01 +00:00 Windows Mobile Device Management Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-24082 2021-02-25 22:01 +00:00 Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
6.5
MEDIUM
CVE-2021-24080 2021-02-25 22:01 +00:00 Windows Trust Verification API Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-24081 2021-02-25 22:01 +00:00 Microsoft Windows Codecs Library Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-24079 2021-02-25 22:01 +00:00 Windows Backup Engine Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-24077 2021-02-25 22:01 +00:00 Windows Fax Service Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-24078 2021-02-25 22:01 +00:00 Windows DNS Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-24076 2021-02-25 22:01 +00:00 Microsoft Windows VMSwitch Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-24075 2021-02-25 22:01 +00:00 Microsoft Windows VMSwitch Denial of Service Vulnerability
6.8
MEDIUM
CVE-2021-1734 2021-02-25 22:01 +00:00 Windows Remote Procedure Call Information Disclosure Vulnerability
7.5
HIGH
CVE-2021-1731 2021-02-25 22:01 +00:00 PFX Encryption Security Feature Bypass Vulnerability
5.5
MEDIUM
CVE-2021-1726 2021-02-25 22:01 +00:00 Microsoft SharePoint Server Spoofing Vulnerability
8
HIGH
CVE-2021-1727 2021-02-25 22:01 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1722 2021-02-25 22:01 +00:00 Windows Fax Service Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-1698 2021-02-25 22:01 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1710 2021-01-12 18:42 +00:00 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1708 2021-01-12 18:42 +00:00 Windows GDI+ Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2021-1709 2021-01-12 18:42 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1706 2021-01-12 18:42 +00:00 Windows LUAFV Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-1703 2021-01-12 18:42 +00:00 Windows Event Logging Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1704 2021-01-12 18:42 +00:00 Windows Hyper-V Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1702 2021-01-12 18:42 +00:00 Windows Remote Procedure Call Runtime Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1700 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1701 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1699 2021-01-12 18:42 +00:00 Windows (modem.sys) Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1696 2021-01-12 18:42 +00:00 Windows Graphics Component Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1697 2021-01-12 18:42 +00:00 Windows InstallService Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1694 2021-01-12 18:42 +00:00 Windows Update Stack Elevation of Privilege Vulnerability
9.8
CRITICAL
CVE-2021-1695 2021-01-12 18:42 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1693 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1691 2021-01-12 18:42 +00:00 Windows Hyper-V Denial of Service Vulnerability
7.7
HIGH
CVE-2021-1688 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1689 2021-01-12 18:42 +00:00 Windows Multipoint Management Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1685 2021-01-12 18:42 +00:00 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1684 2021-01-12 18:42 +00:00 Windows Bluetooth Security Feature Bypass Vulnerability
5.5
MEDIUM
CVE-2021-1682 2021-01-12 18:42 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1683 2021-01-12 18:42 +00:00 Windows Bluetooth Security Feature Bypass Vulnerability
5.5
MEDIUM
CVE-2021-1679 2021-01-12 18:42 +00:00 Windows CryptoAPI Denial of Service Vulnerability
6.5
MEDIUM
CVE-2021-1680 2021-01-12 18:42 +00:00 Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1678 2021-01-12 18:42 +00:00 Windows Print Spooler Spoofing Vulnerability
8.8
HIGH
CVE-2021-1676 2021-01-12 18:42 +00:00 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1673 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1674 2021-01-12 18:42 +00:00 Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
8.8
HIGH
CVE-2021-1672 2021-01-12 18:42 +00:00 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1670 2021-01-12 18:42 +00:00 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1671 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1669 2021-01-12 18:42 +00:00 Windows Remote Desktop Security Feature Bypass Vulnerability
8.8
HIGH
CVE-2021-1668 2021-01-12 18:42 +00:00 Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1666 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1667 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1664 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1665 2021-01-12 18:42 +00:00 GDI+ Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1663 2021-01-12 18:42 +00:00 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1662 2021-01-12 18:42 +00:00 Windows Event Tracing Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1660 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1661 2021-01-12 18:42 +00:00 Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1658 2021-01-12 18:42 +00:00 Remote Procedure Call Runtime Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1659 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1657 2021-01-12 18:42 +00:00 Windows Fax Compose Form Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1655 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1656 2021-01-12 18:42 +00:00 TPM Device Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1654 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1652 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1653 2021-01-12 18:42 +00:00 Windows CSC Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1651 2021-01-12 18:42 +00:00 Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1649 2021-01-12 18:42 +00:00 Active Template Library Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1650 2021-01-12 18:42 +00:00 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1648 2021-01-12 18:42 +00:00 Microsoft splwow64 Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1646 2021-01-12 18:42 +00:00 Windows WLAN Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1645 2021-01-12 18:41 +00:00 Windows Docker Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1642 2021-01-12 18:41 +00:00 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2021-1638 2021-01-12 18:41 +00:00 Windows Bluetooth Security Feature Bypass Vulnerability
7.7
HIGH
CVE-2021-1637 2021-01-12 18:41 +00:00 Windows DNS Query Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17140 2020-12-09 22:36 +00:00 Windows SMB Information Disclosure Vulnerability
8.1
HIGH
CVE-2020-17139 2020-12-09 22:36 +00:00 Windows Overlay Filter Security Feature Bypass Vulnerability
7.8
HIGH
CVE-2020-17136 2020-12-09 22:36 +00:00 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17137 2020-12-09 22:36 +00:00 DirectX Graphics Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17134 2020-12-09 22:36 +00:00 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17103 2020-12-09 22:36 +00:00 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17096 2020-12-09 22:36 +00:00 Windows NTFS Remote Code Execution Vulnerability
8.8
HIGH
CVE-2020-17097 2020-12-09 22:36 +00:00 Windows Digital Media Receiver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17098 2020-12-09 22:36 +00:00 Windows GDI+ Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17094 2020-12-09 22:36 +00:00 Windows Error Reporting Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17095 2020-12-09 22:36 +00:00 Windows Hyper-V Remote Code Execution Vulnerability
9.9
CRITICAL
CVE-2020-17092 2020-12-09 22:36 +00:00 Windows Network Connections Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16996 2020-12-09 22:36 +00:00 Kerberos Security Feature Bypass Vulnerability
6.5
MEDIUM
CVE-2020-16964 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16961 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16962 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16963 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16959 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16960 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16958 2020-12-09 22:36 +00:00 Windows Backup Engine Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-1599 2020-11-11 05:48 +00:00 Windows Spoofing Vulnerability
5.5
MEDIUM
CVE-2020-17088 2020-11-11 05:48 +00:00 Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17090 2020-11-11 05:48 +00:00 Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
9.8
CRITICAL
CVE-2020-17087 2020-11-11 05:48 +00:00 Windows Kernel Local Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17076 2020-11-11 05:48 +00:00 Windows Update Orchestrator Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17077 2020-11-11 05:48 +00:00 Windows Update Stack Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17074 2020-11-11 05:48 +00:00 Windows Update Orchestrator Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17075 2020-11-11 05:48 +00:00 Windows USO Core Worker Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17071 2020-11-11 05:48 +00:00 Windows Delivery Optimization Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17073 2020-11-11 05:48 +00:00 Windows Update Orchestrator Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17069 2020-11-11 05:48 +00:00 Windows NDIS Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17070 2020-11-11 05:48 +00:00 Windows Update Medic Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17068 2020-11-11 05:48 +00:00 Windows GDI+ Remote Code Execution Vulnerability
7.8
HIGH
CVE-2020-17057 2020-11-11 05:48 +00:00 Windows Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17055 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17056 2020-11-11 05:48 +00:00 Windows Network File System Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17051 2020-11-11 05:48 +00:00 Windows Network File System Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2020-17047 2020-11-11 05:48 +00:00 Windows Network File System Denial of Service Vulnerability
7.5
HIGH
CVE-2020-17045 2020-11-11 05:48 +00:00 Windows KernelStream Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17046 2020-11-11 05:48 +00:00 Windows Error Reporting Denial of Service Vulnerability
5.5
MEDIUM
CVE-2020-17042 2020-11-11 05:48 +00:00 Windows Print Spooler Remote Code Execution Vulnerability
8.8
HIGH
CVE-2020-17043 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17044 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17040 2020-11-11 05:48 +00:00 Windows Hyper-V Security Feature Bypass Vulnerability
9.8
CRITICAL
CVE-2020-17041 2020-11-11 05:48 +00:00 Windows Print Configuration Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17038 2020-11-11 05:48 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17035 2020-11-11 05:48 +00:00 Windows Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17036 2020-11-11 05:48 +00:00 Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17033 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17034 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17031 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17032 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17028 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17029 2020-11-11 05:48 +00:00 Windows Canonical Display Driver Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17030 2020-11-11 05:48 +00:00 Windows MSCTF Server Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17026 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17027 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17024 2020-11-11 05:48 +00:00 Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17025 2020-11-11 05:48 +00:00 Windows Remote Access Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17013 2020-11-11 05:48 +00:00 Win32k Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-17014 2020-11-11 05:48 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17011 2020-11-11 05:48 +00:00 Windows Port Class Library Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17007 2020-11-11 05:48 +00:00 Windows Error Reporting Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17010 2020-11-11 05:48 +00:00 Win32k Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17001 2020-11-11 05:47 +00:00 Windows Print Spooler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-17004 2020-11-11 05:47 +00:00 Windows Graphics Component Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2020-16998 2020-11-11 05:47 +00:00 DirectX Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2020-16997 2020-11-11 05:47 +00:00 Remote Desktop Protocol Server Information Disclosure Vulnerability
7.7
HIGH
CVE-2020-17049 2020-11-10 23:00 +00:00

A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD).

To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the KDC to accept it.

The update addresses this vulnerability by changing how the KDC validates service tickets used with KCD.

7.2
HIGH
CVE-2020-1570 2020-08-17 17:13 +00:00 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked "safe for initialization" in an application or Microsoft Office document that hosts the IE rendering engine. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the scripting engine handles objects in memory.
7.5
HIGH
CVE-2020-1567 2020-08-17 17:13 +00:00 A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a HTML editing attack scenario, an attacker could trick a user into editing a specially crafted file that is designed to exploit the vulnerability. The security update addresses the vulnerability by modifying how MSHTML engine validates input.
7.5
HIGH
CVE-2020-1568 2020-08-17 17:13 +00:00 A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website that contains malicious PDF content. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted PDF content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker's site. The security update addresses the vulnerability by modifying how Microsoft Edge PDF Reader handles objects in memory.
7.5
HIGH
CVE-2020-1564 2020-08-17 17:13 +00:00 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.
7.8
HIGH
CVE-2020-1561 2020-08-17 17:13 +00:00 A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.
8.8
HIGH
CVE-2020-1108 2020-05-21 20:53 +00:00 A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
7.5
HIGH
CVE-2019-0545 2019-01-08 20:00 +00:00 An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
7.5
HIGH
CVE-2018-8421 2018-09-12 22:00 +00:00 A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
9.8
CRITICAL
CVE-2018-8424 2018-09-12 22:00 +00:00 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8422.
6.5
MEDIUM
CVE-2018-8434 2018-09-12 22:00 +00:00 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
5.4
MEDIUM
CVE-2018-8360 2018-08-15 15:00 +00:00 An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
7.5
HIGH
CVE-2018-8202 2018-07-10 22:00 +00:00 An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
7.8
HIGH
CVE-2018-8284 2018-07-10 22:00 +00:00 A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
8.1
HIGH
CVE-2018-8356 2018-07-10 22:00 +00:00 A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, ASP.NET Core 2.0, ASP.NET Core 1.0, .NET Core 1.1, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 1.0, .NET Core 2.0, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
5.5
MEDIUM
CVE-2018-0982 2018-06-14 10:00 +00:00 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
7
HIGH
CVE-2018-8142 2018-05-21 11:00 +00:00 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1035.
5.3
MEDIUM
CVE-2018-1039 2018-05-09 17:00 +00:00 A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
7.8
HIGH
CVE-2018-8127 2018-05-09 17:00 +00:00 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8141.
5.5
MEDIUM
CVE-2018-8129 2018-05-09 17:00 +00:00 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0854, CVE-2018-0958, CVE-2018-8132.
5.3
MEDIUM
CVE-2018-8132 2018-05-09 17:00 +00:00 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0854, CVE-2018-0958, CVE-2018-8129.
5.3
MEDIUM
CVE-2018-8134 2018-05-09 17:00 +00:00 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
7
HIGH
CVE-2018-8136 2018-05-09 17:00 +00:00 A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
7.8
HIGH
CVE-2018-0887 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0960 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0968 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0969 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0970 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0971 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0972 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0973 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0974, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0974 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0975.
5.5
MEDIUM
CVE-2018-0975 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0887, CVE-2018-0960, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974.
5.5
MEDIUM
CVE-2018-0981 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0987, CVE-2018-0989, CVE-2018-1000.
5.3
MEDIUM
CVE-2018-0987 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0989, CVE-2018-1000.
4.3
MEDIUM
CVE-2018-0988 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0996, CVE-2018-1001.
7.5
HIGH
CVE-2018-0989 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-1000.
4.3
MEDIUM
CVE-2018-0991 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0870, CVE-2018-0997, CVE-2018-1018, CVE-2018-1020.
7.5
HIGH
CVE-2018-0996 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0988, CVE-2018-1001.
7.5
HIGH
CVE-2018-0997 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-1018, CVE-2018-1020.
7.5
HIGH
CVE-2018-0998 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0892.
4.3
MEDIUM
CVE-2018-1000 2018-04-11 23:00 +00:00 An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-0989.
5.3
MEDIUM
CVE-2018-1001 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0988, CVE-2018-0996.
7.5
HIGH
CVE-2018-1008 2018-04-11 23:00 +00:00 An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
7
HIGH
CVE-2018-1009 2018-04-11 23:00 +00:00 An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
7.8
HIGH
CVE-2018-1018 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-0997, CVE-2018-1020.
7.5
HIGH
CVE-2018-1020 2018-04-11 23:00 +00:00 A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0870, CVE-2018-0991, CVE-2018-0997, CVE-2018-1018.
7.5
HIGH
CVE-2018-0986 2018-04-04 15:00 +00:00 A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.
8.8
HIGH
CVE-2018-0872 2018-03-13 23:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0873, CVE-2018-0874, CVE-2018-0930, CVE-2018-0931, CVE-2018-0933, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.
7.5
HIGH
CVE-2018-0873 2018-03-13 23:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0874, CVE-2018-0930, CVE-2018-0931, CVE-2018-0933, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.
7.5
HIGH
CVE-2018-0874 2018-03-13 23:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0930, CVE-2018-0931, CVE-2018-0933, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.
7.5
HIGH
CVE-2018-0889 2018-03-13 23:00 +00:00 Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876, CVE-2018-0893, CVE-2018-0925, and CVE-2018-0935.
7.5
HIGH
CVE-2018-0891 2018-03-13 23:00 +00:00 ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0939.
4.3
MEDIUM
CVE-2018-0893 2018-03-13 23:00 +00:00 Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0876, CVE-2018-0889, CVE-2018-0925, and CVE-2018-0935.
7.5
HIGH
CVE-2018-0927 2018-03-13 23:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows information disclosure, due to how Microsoft browsers handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability".
4.3
MEDIUM
CVE-2018-0931 2018-03-13 23:00 +00:00 ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0874, CVE-2018-0930, CVE-2018-0933, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.
7.5
HIGH
CVE-2018-0932 2018-03-13 23:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows information disclosure, due to how Microsoft browsers handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability".
4.3
MEDIUM
CVE-2018-0820 2018-02-15 01:00 +00:00 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0756, CVE-2018-0809 and CVE-2018-0843.
7.8
HIGH
CVE-2018-0771 2018-02-12 23:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows a security feature bypass, due to how Edge handles different-origin requests, aka "Microsoft Edge Security Feature Bypass".
4.3
MEDIUM
CVE-2018-0825 2018-02-12 23:00 +00:00 StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how objects are handled in memory, aka "StructuredQuery Remote Code Execution Vulnerability".
7.5
HIGH
CVE-2018-0844 2018-02-12 23:00 +00:00 The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Common Log File System Driver Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0846.
7.8
HIGH
CVE-2018-0846 2018-02-12 23:00 +00:00 The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Common Log File System Driver Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0844.
7.8
HIGH
CVE-2017-11887 2017-12-11 23:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handle objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11906 and CVE-2017-11919.
5.3
MEDIUM
CVE-2017-11906 2017-12-11 23:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11887 and CVE-2017-11919.
5.3
MEDIUM
CVE-2017-11839 2017-11-15 02:00 +00:00 Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to take control of an affected system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11788 2017-11-13 23:00 +00:00 Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to improperly handing objects in memory, aka "Windows Search Denial of Service Vulnerability".
7.5
HIGH
CVE-2017-11791 2017-11-13 23:00 +00:00 ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11834.
3.1
LOW
CVE-2017-11833 2017-11-13 23:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to determine the origin of all webpages in the affected browser, due to how Microsoft Edge handles cross-origin requests, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11803 and CVE-2017-11844.
3.1
LOW
CVE-2017-11834 2017-11-13 23:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11791.
5.3
MEDIUM
CVE-2017-11836 2017-11-13 23:00 +00:00 ChakraCore, and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to take control of an affected system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11837 2017-11-13 23:00 +00:00 ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11838 2017-11-13 23:00 +00:00 ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11840 2017-11-13 23:00 +00:00 ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11841 2017-11-13 23:00 +00:00 ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11843 2017-11-13 23:00 +00:00 ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11846 2017-11-13 23:00 +00:00 ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11847 2017-11-13 23:00 +00:00 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to run arbitrary code in kernel mode, install programs, view, change or delete data, and create new accounts with full user rights due to improperly handing objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability".
7.8
HIGH
CVE-2017-11849 2017-11-13 23:00 +00:00 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11842, CVE-2017-11851, and CVE-2017-11853.
4.7
MEDIUM
CVE-2017-11851 2017-11-13 23:00 +00:00 The Windows kernel component on Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709, allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11842, CVE-2017-11849, and CVE-2017-11853.
4.7
MEDIUM
CVE-2017-11853 2017-11-13 23:00 +00:00 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11842, CVE-2017-11849, and CVE-2017-11851.
5.5
MEDIUM
CVE-2017-11858 2017-11-13 23:00 +00:00 ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Microsoft browsers handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11863 2017-11-13 23:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick a user into loading a page containing malicious content, due to how the Edge Content Security Policy (CSP) validates documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11872 and CVE-2017-11874.
6.1
MEDIUM
CVE-2017-11866 2017-11-13 23:00 +00:00 ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
7.5
HIGH
CVE-2017-11872 2017-11-13 23:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice, due to how Microsoft Edge handles redirect requests, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11863 and CVE-2017-11874.
6.5
MEDIUM
CVE-2017-11811 2017-10-13 11:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11762 2017-10-09 22:00 +00:00 The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.
8.8
HIGH
CVE-2017-11763 2017-10-09 22:00 +00:00 The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.
8.8
HIGH
CVE-2017-11769 2017-10-09 22:00 +00:00 The Microsoft Windows TRIE component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles loading dll files, aka "TRIE Remote Code Execution Vulnerability".
7.8
HIGH
CVE-2017-11771 2017-10-09 22:00 +00:00 The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows Search Remote Code Execution Vulnerability".
9.8
CRITICAL
CVE-2017-11772 2017-10-09 22:00 +00:00 The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure when it fails to properly handle objects in memory, aka "Microsoft Search Information Disclosure Vulnerability".
7.5
HIGH
CVE-2017-11779 2017-10-09 22:00 +00:00 The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability".
8.1
HIGH
CVE-2017-11781 2017-10-09 22:00 +00:00 The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability".
7.5
HIGH
CVE-2017-11782 2017-10-09 22:00 +00:00 The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerability".
7.8
HIGH
CVE-2017-11783 2017-10-09 22:00 +00:00 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka "Windows Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-11798 2017-10-09 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11799 2017-10-09 22:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11800 2017-10-09 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11802 2017-10-09 22:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11804 2017-10-09 22:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11808 2017-10-09 22:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11809, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11809 2017-10-09 22:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11810, CVE-2017-11811, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11812 2017-10-09 22:00 +00:00 ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11812, and CVE-2017-11821.
7.5
HIGH
CVE-2017-11823 2017-10-09 22:00 +00:00 The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass".
6.7
MEDIUM
CVE-2017-11824 2017-10-09 22:00 +00:00 The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles objects in memory, aka "Windows Graphics Component Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-11829 2017-10-09 22:00 +00:00 Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
5.5
MEDIUM
CVE-2017-8689 2017-10-09 22:00 +00:00 The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8694.
7
HIGH
CVE-2017-8693 2017-10-09 22:00 +00:00 The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Microsoft Graphics Information Disclosure Vulnerability".
5.5
MEDIUM
CVE-2017-8694 2017-10-09 22:00 +00:00 The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8689.
7
HIGH
CVE-2017-8715 2017-10-09 22:00 +00:00 The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Windows Security Feature Bypass".
5.3
MEDIUM
CVE-2017-8717 2017-10-09 22:00 +00:00 The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due to how it handles objects in memory, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8718.
7.8
HIGH
CVE-2017-8718 2017-10-09 22:00 +00:00 The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due to how it handles objects in memory, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8717.
7.8
HIGH
CVE-2017-8726 2017-10-09 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11794 and CVE-2017-11803.
4.3
MEDIUM
CVE-2017-8727 2017-10-09 22:00 +00:00 Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to how Microsoft Windows Text Services Framework handles objects in memory, aka "Windows Shell Memory Corruption Vulnerability".
7.5
HIGH
CVE-2017-8686 2017-09-12 23:00 +00:00 The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".
9.8
CRITICAL
CVE-2017-8731 2017-09-12 23:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8734, CVE-2017-8751, and CVE-2017-11766.
7.5
HIGH
CVE-2017-0161 2017-09-11 22:00 +00:00 The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code Execution Vulnerability".
8.1
HIGH
CVE-2017-11766 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-8751.
7.5
HIGH
CVE-2017-8643 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a malicious website open during user clipboard activities, due to the way that Microsoft Edge handles clipboard events, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8597 and CVE-2017-8648.
4.3
MEDIUM
CVE-2017-8649 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8660 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
8.8
HIGH
CVE-2017-8675 2017-09-11 22:00 +00:00 The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".. This CVE ID is unique from CVE-2017-8720.
7
HIGH
CVE-2017-8676 2017-09-11 22:00 +00:00 The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an authenticated attacker to retrieve information from a targeted system via a specially crafted application, aka "Windows GDI+ Information Disclosure Vulnerability."
3.3
LOW
CVE-2017-8677 2017-09-11 22:00 +00:00 The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly discloses kernel memory addresses, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8680, CVE-2017-8681, and CVE-2017-8687.
5.5
MEDIUM
CVE-2017-8678 2017-09-11 22:00 +00:00 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8677, CVE-2017-8680, CVE-2017-8681, and CVE-2017-8687.
5.5
MEDIUM
CVE-2017-8679 2017-09-11 22:00 +00:00 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8708, CVE-2017-8709, and CVE-2017-8719.
5.5
MEDIUM
CVE-2017-8681 2017-09-11 22:00 +00:00 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8680, CVE-2017-8677, and CVE-2017-8687.
5.5
MEDIUM
CVE-2017-8687 2017-09-11 22:00 +00:00 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8680, CVE-2017-8677, and CVE-2017-8681.
5.5
MEDIUM
CVE-2017-8688 2017-09-11 22:00 +00:00 Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and CVE-2017-8685.
5.5
MEDIUM
CVE-2017-8695 2017-09-11 22:00 +00:00 Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to obtain information to further compromise a user's system via a specially crafted document or an untrusted webpage, aka "Graphics Component Information Disclosure Vulnerability."
5.3
MEDIUM
CVE-2017-8699 2017-09-11 22:00 +00:00 Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to run arbitrary code in the context of the current user, due to the way that Windows Shell validates file copy destinations, aka "Windows Shell Remote Code Execution Vulnerability".
7
HIGH
CVE-2017-8702 2017-09-11 22:00 +00:00 Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows an attacker to gain greater access to sensitive information and system functionality, due to the way that WER handles and executes files, aka "Windows Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-8704 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability".
5.3
MEDIUM
CVE-2017-8706 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
5.3
MEDIUM
CVE-2017-8707 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8706, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
5.3
MEDIUM
CVE-2017-8708 2017-09-11 22:00 +00:00 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8679, CVE-2017-8709, and CVE-2017-8719.
4.7
MEDIUM
CVE-2017-8711 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8706, CVE-2017-8712, and CVE-2017-8713.
5.3
MEDIUM
CVE-2017-8712 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8706, and CVE-2017-8713.
5.3
MEDIUM
CVE-2017-8713 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8706.
5.3
MEDIUM
CVE-2017-8714 2017-09-11 22:00 +00:00 The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Remote Desktop Virtual Host Remote Code Execution Vulnerability".
7.8
HIGH
CVE-2017-8723 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8754.
4.3
MEDIUM
CVE-2017-8728 2017-09-11 22:00 +00:00 Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Windows PDF Library handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8737.
7.5
HIGH
CVE-2017-8734 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8751, and CVE-2017-11766.
7.5
HIGH
CVE-2017-8735 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge Spoofing Vulnerability". This CVE ID is unique from CVE-2017-8724.
4.3
MEDIUM
CVE-2017-8736 2017-09-11 22:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to obtain specific information used in the parent domain, due to Microsoft browser parent domain verification in certain functionality, aka "Microsoft Browser Information Disclosure Vulnerability".
4.3
MEDIUM
CVE-2017-8737 2017-09-11 22:00 +00:00 Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Windows PDF Library handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8728.
7.5
HIGH
CVE-2017-8738 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8741 2017-09-11 22:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8748 2017-09-11 22:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8750 2017-09-11 22:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability".
7.5
HIGH
CVE-2017-8752 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8753 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8754 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8723.
4.2
MEDIUM
CVE-2017-8755 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8756 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, and CVE-2017-11764.
7.5
HIGH
CVE-2017-8757 2017-09-11 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way Microsoft Edge handles objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability".
7.5
HIGH
CVE-2017-8671 2017-08-08 19:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-0174 2017-08-07 22:00 +00:00 Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka "Windows NetBIOS Denial of Service Vulnerability".
6.5
MEDIUM
CVE-2017-0250 2017-08-07 22:00 +00:00 Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to buffer overflow, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability".
7.8
HIGH
CVE-2017-0293 2017-08-07 22:00 +00:00 Microsoft Windows PDF Library in Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability".
7.5
HIGH
CVE-2017-8503 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642.
8.8
HIGH
CVE-2017-8591 2017-08-07 22:00 +00:00 Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, aka "Windows IME Remote Code Execution Vulnerability".
7.8
HIGH
CVE-2017-8593 2017-08-07 22:00 +00:00 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-8623 2017-08-07 22:00 +00:00 Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability".
6.8
MEDIUM
CVE-2017-8624 2017-08-07 22:00 +00:00 CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
7.8
HIGH
CVE-2017-8633 2017-08-07 22:00 +00:00 Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability, aka "Windows Error Reporting Elevation of Privilege Vulnerability".
7.5
HIGH
CVE-2017-8639 2017-08-07 22:00 +00:00 Microsoft Edge in Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8640 2017-08-07 22:00 +00:00 Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8641 2017-08-07 22:00 +00:00 Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8644 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8652 and CVE-2017-8662.
4.3
MEDIUM
CVE-2017-8645 2017-08-07 22:00 +00:00 Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8646 2017-08-07 22:00 +00:00 Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8652 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8662.
6.5
MEDIUM
CVE-2017-8653 2017-08-07 22:00 +00:00 Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly accessing objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8669.
7.5
HIGH
CVE-2017-8655 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8656 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8657 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8661 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability".
7.5
HIGH
CVE-2017-8664 2017-08-07 22:00 +00:00 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability".
8.8
HIGH
CVE-2017-8666 2017-08-07 22:00 +00:00 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly handle objects in memory, aka "Win32k Information Disclosure Vulnerability".
5.5
MEDIUM
CVE-2017-8669 2017-08-07 22:00 +00:00 Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly handling objects in memory while rendering content, aka "Microsoft Browser Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8653.
7.5
HIGH
CVE-2017-8670 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8672 2017-08-07 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, and CVE-2017-8674.
7.5
HIGH
CVE-2017-8518 2017-08-03 22:00 +00:00 Microsoft Edge allows a remote code execution vulnerability due to the way it accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
7.5
HIGH
CVE-2017-0170 2017-07-10 22:00 +00:00 Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerability".
6.5
MEDIUM
CVE-2017-8463 2017-07-10 22:00 +00:00 Windows Shell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it improperly handles executable files and shares during rename operations, aka "Windows Explorer Remote Code Execution Vulnerability".
7.8
HIGH
CVE-2017-8467 2017-07-10 22:00 +00:00 Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-8486 2017-07-10 22:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, aka "Win32k Information Disclosure Vulnerability".
4.7
MEDIUM
CVE-2017-8495 2017-07-10 22:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNAME Security Feature Bypass Vulnerability" or Orpheus' Lyre.
7.5
HIGH
CVE-2017-8556 2017-07-10 22:00 +00:00 Graphics in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8573 and CVE-2017-8574.
7
HIGH
CVE-2017-8561 2017-07-10 22:00 +00:00 Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-8562 2017-07-10 22:00 +00:00 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows improperly handling calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-8563 2017-07-10 22:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerberos falling back to NT LAN Manager (NTLM) Authentication Protocol as the default authentication protocol, aka "Windows Elevation of Privilege Vulnerability".
8.1
HIGH
CVE-2017-8565 2017-07-10 22:00 +00:00 Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when PSObject wraps a CIM Instance, aka "Windows PowerShell Remote Code Execution Vulnerability".
8.1
HIGH
CVE-2017-8566 2017-07-10 22:00 +00:00 Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability".
7
HIGH
CVE-2017-8573 2017-07-10 22:00 +00:00 Graphics in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8574 and CVE-2017-8556.
7
HIGH
CVE-2017-8574 2017-07-10 22:00 +00:00 Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8573 and CVE-2017-8556.
7
HIGH
CVE-2017-8577 2017-07-10 22:00 +00:00 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8578, CVE-2017-8580, CVE-2017-8581, and CVE-2017-8467.
7
HIGH
CVE-2017-8578 2017-07-10 22:00 +00:00 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8577, CVE-2017-8580, CVE-2017-8581, and CVE-2017-8467.
7.8
HIGH
CVE-2017-8580 2017-07-10 22:00 +00:00 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8577, CVE-2017-8578, CVE-2017-8581, and CVE-2017-8467.
7
HIGH
CVE-2017-8581 2017-07-10 22:00 +00:00 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8578, CVE-2017-8580, CVE-2017-8577, and CVE-2017-8467.
7
HIGH
CVE-2017-8582 2017-07-10 22:00 +00:00 HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability".
5.9
MEDIUM
CVE-2017-8584 2017-07-10 22:00 +00:00 Windows 10 1607 and Windows Server 2016 allow an attacker to execute code remotely via a specially crafted WiFi packet aka "HoloLens Remote Code Execution Vulnerability."
7.5
HIGH
CVE-2017-8588 2017-07-10 22:00 +00:00 Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially crafted files, aka "WordPad Remote Code Execution Vulnerability".
7
HIGH
CVE-2017-8589 2017-07-10 22:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
9.8
CRITICAL
CVE-2017-8590 2017-07-10 22:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File System (CLFS) driver handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
8.8
HIGH
CVE-2017-8592 2017-07-10 22:00 +00:00 Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they improperly handle redirect requests, aka "Microsoft Browser Security Feature Bypass".
6.5
MEDIUM
CVE-2017-8595 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8601,CVE-2017-8618, CVE-2017-8619, CVE-2017-8610, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8596 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8598, CVE-2017-8610, CVE-2017-8595, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8598 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8610, CVE-2017-8618, CVE-2017-8619, CVE-2017-8595, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8599 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
6.5
MEDIUM
CVE-2017-8602 2017-07-10 22:00 +00:00 Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
6.5
MEDIUM
CVE-2017-8603 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8610, CVE-2017-8598, CVE-2017-8618, CVE-2017-8619, CVE-2017-8595, CVE-2017-8601, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8604 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8618, CVE-2017-8619, CVE-2017-8601, CVE-2017-8610, CVE-2017-8603, CVE-2017-8598, CVE-2017-8601, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8605 2017-07-10 22:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8601, CVE-2017-8618, CVE-2017-8619, CVE-2017-8610, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8598, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8606 2017-07-10 22:00 +00:00 Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8598, CVE-2017-8596, CVE-2017-8618, CVE-2017-8619, CVE-2017-8610, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8595, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609
7.5
HIGH
CVE-2017-8607 2017-07-10 22:00 +00:00 Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8598, CVE-2017-8596, CVE-2017-8618, CVE-2017-8619, CVE-2017-8610, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8595, CVE-2017-8606, CVE-2017-8608, and CVE-2017-8609
7.5
HIGH
CVE-2017-8608 2017-07-10 22:00 +00:00 Microsoft browsers in Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8598, CVE-2017-8596, CVE-2017-8610, CVE-2017-8601, CVE-2017-8618, CVE-2017-8619, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8595, CVE-2017-8606, CVE-2017-8607, and CVE-2017-8609
7.5
HIGH
CVE-2017-8609 2017-07-10 22:00 +00:00 Microsoft Internet Explorer in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8596, CVE-2017-8610, CVE-2017-8618, CVE-2017-8619, CVE-2017-8595, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, and CVE-2017-8609.
7.5
HIGH
CVE-2017-8619 2017-07-10 22:00 +00:00 Microsoft Edge on Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way affected Microsoft scripting engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-8596, CVE-2017-8610, CVE-2017-8601, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, CVE-2017-8618, CVE-2017-9598 and CVE-2017-8609.
7.5
HIGH
CVE-2017-8554 2017-06-29 11:00 +00:00 The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via a specially crafted application.
4.7
MEDIUM
CVE-2017-8575 2017-06-29 11:00 +00:00 The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application, aka "Microsoft Graphics Component Information Disclosure Vulnerability."
5.5
MEDIUM
CVE-2017-8576 2017-06-29 11:00 +00:00 The graphics component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability."
7
HIGH
CVE-2017-8579 2017-06-29 11:00 +00:00 The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability."
7
HIGH
CVE-2017-0291 2017-06-14 23:00 +00:00 Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0292.
7.8
HIGH
CVE-2017-0292 2017-06-14 23:00 +00:00 Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0291.
7.8
HIGH
CVE-2017-0294 2017-06-14 23:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute remote code when Windows fails to properly handle cabinet files, aka "Windows Remote Code Execution Vulnerability".
7.8
HIGH
CVE-2017-0295 2017-06-14 23:00 +00:00 Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".
5.5
MEDIUM
CVE-2017-0296 2017-06-14 23:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to elevate privilege when tdx.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows TDX Elevation of Privilege Vulnerability".
7.8
HIGH
CVE-2017-0297 2017-06-14 23:00 +00:00 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0299, CVE-2017-0300.
5
MEDIUM
CVE-2017-0298 2017-06-14 23:00 +00:00 A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive user, allows an authenticated attacker to run arbitrary code in another user's session, aka "Windows COM Session Elevation of Privilege Vulnerability."
7.3
HIGH
CVE-2017-0299 2017-06-14 23:00 +00:00 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0300, and CVE-2017-0297.
5
MEDIUM
CVE-2017-0300 2017-06-14 23:00 +00:00 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0299, and CVE-2017-0297.
5
MEDIUM
CVE-2017-8474 2017-06-14 23:00 +00:00 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8483, CVE-2017-8482, CVE-2017-8481, CVE-2017-8480, CVE-2017-8478, CVE-2017-8479, CVE-2017-8476, CVE-2017-8469, CVE-2017-8462, CVE-2017-0300, CVE-2017-0299, and CVE-2017-0297.
5
MEDIUM
CVE-2017-8494 2017-06-14 23:00 +00:00 Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows Elevation of Privilege Vulnerability".
7.3
HIGH
CVE-2017-8498 2017-06-14 23:00 +00:00 Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows JavaScript XML DOM objects to detect installed browser extensions, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8504.
4.3
MEDIUM
CVE-2017-8504 2017-06-14 23:00 +00:00 Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8498.
4.3
MEDIUM
CVE-2017-8515 2017-06-14 23:00 +00:00 Microsoft Windows 10 1511, 1607, and 1703, and Windows Server 2016 allow an unauthenticated attacker to send a specially crafted kernel mode request to cause a denial of service on the target system, aka "Windows VAD Cloning Denial of Service Vulnerability".
5.5
MEDIUM
CVE-2017-8523 2017-06-14 23:00 +00:00 Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge fails to correctly apply Same Origin Policy for HTML elements present in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8530 and CVE-2017-8555.
4.3
MEDIUM
CVE-2017-8531 2017-06-14 23:00 +00:00 Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 Service Pack 3, and Microsoft Office 2010 Service Pack 2 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0288, CVE-2017-0289, CVE-2017-8532, and CVE-2017-8533.
6.5
MEDIUM
CVE-2017-8533 2017-06-14 23:00 +00:00 Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0288, CVE-2017-0289, CVE-2017-8531, and CVE-2017-8532.
6.5
MEDIUM
CVE-2017-8544 2017-06-14 23:00 +00:00 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to obtain information to further compromise the user's system when Windows Search fails to handle objects in memory, aka "Windows Search Information Disclosure Vulnerability".
5.5
MEDIUM
CVE-2017-8547 2017-06-14 23:00 +00:00 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8519.
7.5
HIGH
CVE-2017-0190 2017-05-12 12:00 +00:00 The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
4.4
MEDIUM
CVE-2017-0212 2017-05-12 12:00 +00:00 Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability".
7.6
HIGH
CVE-2017-0214 2017-05-12 12:00 +00:00 Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0213.
7
HIGH
CVE-2017-0246 2017-05-12 12:00 +00:00 The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application or in Windows 7 for x64-based Systems and later, cause denial of service, aka "Win32k Elevation of Privilege Vulnerability."
7
HIGH
CVE-2017-0269 2017-05-12 12:00 +00:00 The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
5.9
MEDIUM
CVE-2017-0272 2017-05-12 12:00 +00:00 The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0277, CVE-2017-0278, and CVE-2017-0279.
8.1
HIGH
CVE-2017-0275 2017-05-12 12:00 +00:00 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0276.
5.9
MEDIUM
CVE-2017-0276 2017-05-12 12:00 +00:00 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0275.
5.9
MEDIUM
CVE-2017-0277 2017-05-12 12:00 +00:00 The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0278, and CVE-2017-0279.
7
HIGH
CVE-2017-0058 2017-04-12 12:00 +00:00 A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."
4.7
MEDIUM
CVE-2017-0156 2017-04-12 12:00 +00:00 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle objects in memory, aka "Windows Graphics Component Elevation of Privilege Vulnerability."
7
HIGH
CVE-2017-0158 2017-04-12 12:00 +00:00 An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."
7.5
HIGH
CVE-2017-0159 2017-04-12 12:00 +00:00 A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability."
3.7
LOW
CVE-2017-0162 2017-04-12 12:00 +00:00 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0163, CVE-2017-0180, and CVE-2017-0181.
7.6
HIGH
CVE-2017-0163 2017-04-12 12:00 +00:00 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.
7.6
HIGH
CVE-2017-0164 2017-04-12 12:00 +00:00 A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability."
4.4
MEDIUM
CVE-2017-0166 2017-04-12 12:00 +00:00 An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."
8.1
HIGH
CVE-2017-0167 2017-04-12 12:00 +00:00 An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."
5.5
MEDIUM
CVE-2017-0178 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V running on Windows 10, Windows 10 1511, Windows 10 1607, Windows 8.1, Windows Server 2012 R2, and Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
5.4
MEDIUM
CVE-2017-0179 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
5.8
MEDIUM
CVE-2017-0180 2017-04-12 12:00 +00:00 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0181.
7.6
HIGH
CVE-2017-0181 2017-04-12 12:00 +00:00 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0180.
7.6
HIGH
CVE-2017-0182 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
5.8
MEDIUM
CVE-2017-0183 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
5.8
MEDIUM
CVE-2017-0184 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0185, and CVE-2017-0186.
5.4
MEDIUM
CVE-2017-0185 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0186.
5.8
MEDIUM
CVE-2017-0186 2017-04-12 12:00 +00:00 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, and CVE-2017-0185.
5.8
MEDIUM
CVE-2017-0188 2017-04-12 12:00 +00:00 A Win32k information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0189.
3.3
LOW
CVE-2017-0189 2017-04-12 12:00 +00:00 An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0188.
7.8
HIGH
CVE-2017-0191 2017-04-12 12:00 +00:00 A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding, aka "Windows Denial of Service Vulnerability."
5.8
MEDIUM
CVE-2017-0192 2017-04-12 12:00 +00:00 The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive information via a specially crafted document or an untrusted website, aka "ATMFD.dll Information Disclosure Vulnerability."
4.3
MEDIUM
CVE-2017-0211 2017-04-12 12:00 +00:00 An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege Vulnerability."
5.5
MEDIUM
CVE-2017-0007 2017-03-16 23:00 +00:00 Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability."
5.5
MEDIUM
CVE-2017-0014 2017-03-16 23:00 +00:00 The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.
7.5
HIGH
CVE-2017-0016 2017-03-16 23:00 +00:00 Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a crafted SMBv2 or SMBv3 packet to the Server service, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability."
5.9
MEDIUM
CVE-2017-0021 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from that described in CVE-2017-0095.
9
CRITICAL
CVE-2017-0024 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows 10 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, and CVE-2017-0082.
7.8
HIGH
CVE-2017-0025 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0005, and CVE-2017-0047.
7.8
HIGH
CVE-2017-0026 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, and CVE-2017-0082.
7.8
HIGH
CVE-2017-0042 2017-03-16 23:00 +00:00 Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "Windows Media Player Information Disclosure Vulnerability."
3.1
LOW
CVE-2017-0043 2017-03-16 23:00 +00:00 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active Directory Federation Services Information Disclosure Vulnerability."
5.3
MEDIUM
CVE-2017-0050 2017-03-16 23:00 +00:00 The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2017-0051 2017-03-16 23:00 +00:00 Microsoft Windows 10 1607 and Windows Server 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Hyper-V Network Switch Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, CVE-2017-0098, and CVE-2017-0099.
5.4
MEDIUM
CVE-2017-0055 2017-03-16 23:00 +00:00 Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."
6.1
MEDIUM
CVE-2017-0056 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, CVE-2017-0082.
7.8
HIGH
CVE-2017-0057 2017-03-16 23:00 +00:00 DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to visit an untrusted webpage or (2) tricking a server into sending a DNS query to a malicious DNS server, aka "Windows DNS Query Information Disclosure Vulnerability."
4.3
MEDIUM
CVE-2017-0063 2017-03-16 23:00 +00:00 The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted website, aka "Microsoft Color Management Information Disclosure Vulnerability." This vulnerability is different from that described in CVE-2017-0061.
6.5
MEDIUM
CVE-2017-0074 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.
5.4
MEDIUM
CVE-2017-0075 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0109.
7.6
HIGH
CVE-2017-0076 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0097, and CVE-2017-0099.
5.4
MEDIUM
CVE-2017-0078 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, CVE-2017-0082.
7.8
HIGH
CVE-2017-0080 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0081, and CVE-2017-0082.
7.8
HIGH
CVE-2017-0081 2017-03-16 23:00 +00:00 The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-0026, CVE-2017-0056, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0082.
7.8
HIGH
CVE-2017-0095 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0021.
7.6
HIGH
CVE-2017-0096 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."
2.6
LOW
CVE-2017-0097 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0099.
5.4
MEDIUM
CVE-2017-0098 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0074, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.
5.4
MEDIUM
CVE-2017-0099 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0097.
5.4
MEDIUM
CVE-2017-0109 2017-03-16 23:00 +00:00 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0075.
7.6
HIGH
CVE-2017-0118 2017-03-16 23:00 +00:00 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.
4.3
MEDIUM
CVE-2017-0121 2017-03-16 23:00 +00:00 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerability." CVE-2017-0085, CVE-2017-0091, CVE-2017-0092, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, and CVE-2017-0128.
4.3
MEDIUM
CVE-2017-0038 2017-02-20 15:00 +00:00 gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.
5.5
MEDIUM
CVE-2016-7219 2016-12-20 04:54 +00:00 The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Crypto Driver Information Disclosure Vulnerability."
5.5
MEDIUM
CVE-2016-7258 2016-12-20 04:54 +00:00 The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address Information Disclosure Vulnerability."
5.5
MEDIUM
CVE-2016-7259 2016-12-20 04:54 +00:00 The Graphics Component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7260 2016-12-20 04:54 +00:00 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7271 2016-12-20 04:54 +00:00 The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual trust level (VTL) protection mechanism via a crafted application, aka "Secure Kernel Mode Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7272 2016-12-20 04:54 +00:00 The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."
8.8
HIGH
CVE-2016-7273 2016-12-20 04:54 +00:00 The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."
8.8
HIGH
CVE-2016-7274 2016-12-20 04:54 +00:00 Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."
8.8
HIGH
CVE-2016-7212 2016-11-10 05:16 +00:00 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow remote attackers to execute arbitrary code via a crafted image file, aka "Windows Remote Code Execution Vulnerability."
7.8
HIGH
CVE-2016-7214 2016-11-10 05:16 +00:00 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to bypass the ASLR protection mechanism via a crafted application, aka "Win32k Information Disclosure Vulnerability."
3.3
LOW
CVE-2016-7215 2016-11-10 05:16 +00:00 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7217 2016-11-10 05:16 +00:00 Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Media Foundation Memory Corruption Vulnerability."
8.8
HIGH
CVE-2016-7221 2016-11-10 05:16 +00:00 Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles DLL loading, which allows local users to gain privileges via unspecified vectors, aka "Windows IME Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7237 2016-11-10 05:16 +00:00 Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."
6.5
MEDIUM
CVE-2016-7238 2016-11-10 05:16 +00:00 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandle caching for NTLM password-change requests, which allows local users to gain privileges via a crafted application, aka "Windows NTLM Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7246 2016-11-10 05:16 +00:00 The kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
7.8
HIGH
CVE-2016-7247 2016-11-10 05:16 +00:00 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow physically proximate attackers to bypass the Secure Boot protection mechanism via a crafted boot policy, aka "Secure Boot Component Vulnerability."
7.5
HIGH
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.