230 vulnerabilidades · Windows · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2024-38193
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
73.2%
2024 CWE-416 2 PoCs

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2016-0099
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
90.4%
2016 4 PoCs

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."

CVE-2013-3660
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
70.6%
2013 4 PoCs

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."

CVE-2020-0683
🔥 KEV Windows Windows
7.8
HIGH
EPSS
31.1%
2020 4 PoCs

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

CVE-2024-38080
🔥 KEV Windows Server 2022 Windows
7.8
HIGH
EPSS
13.7%
2024 CWE-190 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2021-36955
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
20.7%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2015-3043
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
87.4%
2015 1 PoC

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

CVE-2021-36934
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
91.0%
2021 16 PoCs

<p>An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>An attacker must have the ability to execute code on a victim system to exploit this vulnerability.</p> <p>After installing this security update, you <em>must</em> manually delete

CVE-2021-34486
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
36.5%
2021 2 PoCs

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-43226
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.4%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2009-1123
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
5.2%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

CVE-2016-0185
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
80.2%
2016 1 PoC

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

CVE-2024-30051
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
43.5%
2024 CWE-122 1 PoC

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2009-4324
🔥 KEV Software Genérico Web Windows
7.8
HIGH
EPSS
92.9%
2009 2 PoCs

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

CVE-2022-41073
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-21999
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
73.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2010-1297
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.8%
2010 4 PoCs

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.