1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-30164
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Kerberos AppContainer Security Feature Bypass Vulnerability

CVE-2022-35768
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-41073
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-40126
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.

CVE-2022-34705
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Windows Defender Credential Guard Elevation of Privilege Vulnerability

CVE-2022-34672
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-284 1 PoC

NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or executing commands.

CVE-2022-22718
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.7%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-0166
McAfee Agent for Windows Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

CVE-2022-34711
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.7%
2022 1 PoC

Windows Defender Credential Guard Elevation of Privilege Vulnerability

CVE-2022-46693
iCloud for Windows Cloud Windows
7.8
HIGH
EPSS
0.2%
2022 4 PoCs

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVE-2022-45770
Software Genérico Windows
7.8
HIGH
EPSS
0.7%
2022 3 PoCs

Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.

CVE-2022-25365
Software Genérico DevOps Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.

CVE-2022-34707
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.5%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-21491
VM VirtualBox Database Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows systems only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I

CVE-2022-3605
WP CSV Exporter Web Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.

CVE-2022-30190
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
93.6%
2022 75 PoCs

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

CVE-2022-48622
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbuf_set_option() in gdk-pixbuf.c.

CVE-2022-41975
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.

CVE-2022-37326
Software Genérico DevOps Web Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.