2040 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-43229
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
11.9%
2021 1 PoC

Windows NTFS Elevation of Privilege Vulnerability

CVE-2021-26871
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
1.4%
2021 2 PoCs

Windows WalletService Elevation of Privilege Vulnerability

CVE-2021-1727
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.1%
2021 1 PoC

Windows Installer Elevation of Privilege Vulnerability

CVE-2021-1366
Cisco AnyConnect Secure Mobility Client Networking Windows
7.8
HIGH
EPSS
0.6%
2021 CWE-347 1 PoC

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affect

CVE-2021-42954
Software Genérico Windows
7.8
HIGH
EPSS
0.0%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.

CVE-2021-38639
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2021 1 PoC

Win32k Elevation of Privilege Vulnerability

CVE-2021-28310
🔥 KEV Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
54.0%
2021 1 PoC

Win32k Elevation of Privilege Vulnerability

CVE-2021-24091
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
15.5%
2021 1 PoC

Windows Camera Codec Pack Remote Code Execution Vulnerability

CVE-2021-35538
VM VirtualBox Database Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.28. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability does not apply to Windows systems. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H

CVE-2021-31169
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31954
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.3%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-28321
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
1.1%
2021 2 PoCs

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

CVE-2021-26882
Windows 10 Version 1803 Web Windows
7.8
HIGH
EPSS
4.2%
2021 2 PoCs

Remote Access API Elevation of Privilege Vulnerability

CVE-2021-36955
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
20.7%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-24096
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
5.7%
2021 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-31165
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31167
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 2 PoCs

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-28322
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.7%
2021 2 PoCs

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

CVE-2021-42956
Software Genérico Windows
7.8
HIGH
EPSS
0.2%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.