1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-0121
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-50591
Elefant Software Updater Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-77 2 PoCs

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as "SYSTEM" via Windows Named Pipes.The Elefant Software Updater (ESU) consists of two components. An ESU service which runs as "NT AUTHORITY\SYSTEM" and an ESU tray client which communicates with the service to update or repair the installation and is running with user permission

CVE-2024-13759
Prime Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attackers to gain system-level privileges via arbitrary file deletion

CVE-2024-38100
Windows Server 2019 Windows
7.8
HIGH
EPSS
30.8%
2024 CWE-284 1 PoC

Windows File Explorer Elevation of Privilege Vulnerability

CVE-2024-13961
CleanUp Premium Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

CVE-2024-38080
🔥 KEV Windows Server 2022 Windows
7.8
HIGH
EPSS
13.7%
2024 CWE-190 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-38249
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.6%
2024 CWE-416 1 PoC

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2024-0107
GPU Display Driver, vGPU Software, Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.3%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-43630
Windows Server 2022 Windows
7.8
HIGH
EPSS
3.6%
2024 CWE-121 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-21111
VM VirtualBox Database Windows
7.8
HIGH
EPSS
11.1%
2024 5 PoCs

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I

CVE-2024-23144
AutoCAD Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-787 1 PoC

A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

CVE-2024-0071
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-125 2 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-22002
Software Genérico Windows
7.8
HIGH
EPSS
2.4%
2024 1 PoC

CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.

CVE-2024-7977
Chrome Windows
7.8
HIGH
EPSS
0.0%
2024 1 PoC

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)

CVE-2024-0120
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-43583
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
3.7%
2024 CWE-250 2 PoCs

Winlogon Elevation of Privilege Vulnerability

CVE-2024-26230
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
46.7%
2024 CWE-416 2 PoCs

Windows Telephony Server Elevation of Privilege Vulnerability

CVE-2024-13944
Norton Utilities Ultimate Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-367 1 PoC

Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.