4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4294
Norton Antivirus Windows Eraser Engine Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2022-28184
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.

CVE-2022-34292
Software Genérico DevOps Web Windows
7.1
HIGH
EPSS
0.0%
2022 1 PoC

Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647.

CVE-2026-21253
Windows 10 Version 1607 Windows
7.0
HIGH
EPSS
0.1%
2026 CWE-416 2 PoCs

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

CVE-2023-28229
🔥 KEV Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
8.6%
2023 CWE-591 1 PoC

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2023-5097
Workforce Access Windows
7.0
HIGH
EPSS
0.1%
2023 CWE-22 1 PoC

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

CVE-2023-21739
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
0.4%
2023 CWE-591 1 PoC

Windows Bluetooth Driver Elevation of Privilege Vulnerability

CVE-2023-36427
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
9.9%
2023 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2023-28218
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
30.4%
2023 CWE-122 1 PoC

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2023-36403
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
0.2%
2023 CWE-591 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-39708
Software Genérico Windows
7.0
HIGH
EPSS
0.0%
2024 1 PoC

An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy a crafted DLL file to a temporary directory (used by .NET Shadow Copies) such that privilege escalation can occur if the core agent service loads that file.

CVE-2024-12310
Enterprise Access Management Windows
7.0
HIGH
EPSS
0.0%
2024 CWE-287 1 PoC

A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts. This issue affects Imprivata Enterprise Access Management versions 5.3 through 24.2.

CVE-2024-42050
Software Genérico Windows
7.0
HIGH
EPSS
0.0%
2024 1 PoC

The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.

CVE-2024-30090
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
20.9%
2024 CWE-822 1 PoC

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVE-2024-50592
Elefant Software Updater Windows
7.0
HIGH
EPSS
0.1%
2024 CWE-367 2 PoCs

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process. When using the repair function, the service queries the server for a list of files and their hashes. In addition, instructions to execute binaries to finalize the repair process are included. The executables are executed as "NT AUTHORITY\SYSTEM" after they are copied over to the user writable installation folder (C:\Elefant1). This means that a user can overwrite ei

CVE-2019-1041
Windows 10 Version 1803 Windows
7.0
HIGH
EPSS
0.2%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application to take control of an affected system. The update addresses the vulnerability by correcting how the Windows kernel handles ob

CVE-2019-3585
McAfee VirusScan Enterprise (VSE) Windows
7.0
HIGH
EPSS
0.0%
2019 CWE-269 1 PoC

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges.

CVE-2019-16784
PyInstaller Windows
7.0
HIGH
EPSS
3.2%
2019 CWE-250 1 PoC

In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which have his "TempPath" resolving to a world writable directory. This is the case for example if the software is launched as a service or as a scheduled task using a system account (TempPath will be C:\Windows\Temp). In order to be exploitable the software has to be (re)started after the attacker launch the exploit program, so for a service laun

CVE-2021-26863
Windows 10 Version 1803 Windows
7.0
HIGH
EPSS
0.2%
2021 1 PoC

Windows Win32k Elevation of Privilege Vulnerability