2040 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-30164
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Kerberos AppContainer Security Feature Bypass Vulnerability

CVE-2022-21999
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
73.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-38037
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
3.0%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-36929
Zoom Rooms for Windows Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-367 1 PoC

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

CVE-2022-38777
Elastic Endpoint Security Windows
7.8
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

CVE-2022-1256
McAfee Agent for Windows Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges through manipulation of symbolic links.

CVE-2022-41073
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-41057
Windows 10 Version 1809 Web Windows
7.8
HIGH
EPSS
1.1%
2022 2 PoCs

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2022-35771
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.4%
2022 1 PoC

Windows Defender Credential Guard Elevation of Privilege Vulnerability

CVE-2022-45770
Software Genérico Windows
7.8
HIGH
EPSS
0.7%
2022 3 PoCs

Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.

CVE-2022-46693
iCloud for Windows Cloud Windows
7.8
HIGH
EPSS
0.2%
2022 4 PoCs

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVE-2022-30166
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.6%
2022 1 PoC

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2022-25365
Software Genérico DevOps Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.

CVE-2022-21974
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.8%
2022 1 PoC

Roaming Security Rights Management Services Remote Code Execution Vulnerability

CVE-2022-35768
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-34707
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.5%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-48622
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbuf_set_option() in gdk-pixbuf.c.