4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-38127
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.1%
2024 CWE-126 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-26230
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
46.7%
2024 CWE-416 2 PoCs

Windows Telephony Server Elevation of Privilege Vulnerability

CVE-2024-0090
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.3%
2024 CWE-787 1 PoC

NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-13960
TuneUp Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

CVE-2024-30085
Windows 11 version 21H2 Cloud Windows
7.8
HIGH
EPSS
55.2%
2024 CWE-122 2 PoCs

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2024-0091
GPU display driver, vGPU software, and Cloud Gaming Web Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-822 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVE-2024-29863
Software Genérico Windows
7.8
HIGH
EPSS
3.2%
2024 2 PoCs

A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.

CVE-2024-23143
AutoCAD Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-125 1 PoC

A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.

CVE-2024-23774
Software Genérico Windows
7.8
HIGH
EPSS
0.5%
2024 1 PoC

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KSchedulerSvc.exe and AMPTools.exe components. This allows local attackers to execute code of their choice with NT Authority\SYSTEM privileges.

CVE-2024-13961
CleanUp Premium Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

CVE-2024-38193
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
73.2%
2024 CWE-416 2 PoCs

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-26218
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
21.9%
2024 CWE-367 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-49019
Windows Server 2019 Windows
7.8
HIGH
EPSS
4.8%
2024 CWE-1390 1 PoC

Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2024-42052
Software Genérico Windows
7.8
HIGH
EPSS
0.0%
2024 1 PoC

The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a wevtutil.exe file in the folder.

CVE-2024-9524
Prime Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-59 1 PoC

Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

CVE-2024-13944
Norton Utilities Ultimate Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-367 1 PoC

Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

CVE-2024-50590
Elefant Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-276 2 PoCs

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory of Elefant is "C:\Elefant1" which is writable for all users. In addition, the Elefant installer registers two Firebird database services which are running as “NT AUTHORITY\SYSTEM”.  Path: C:\Elefant1\Firebird_2\bin\fbserver.exe Path: C:\Elefant1\Firebird_2\bin\fbguard.exe Both service binaries are user writable. This means that a local attacker can rena