578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-37047
Deep Instinct Windows Agent Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2020-36979
Coex Service Application Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.

CVE-2020-36903
Selea CarPlateServer (CPS) Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 2 PoCs

Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during application startup or reboot.

CVE-2020-4204
DB2 for Linux- UNIX and Windows Windows
8.4
HIGH
EPSS
0.1%
2020 1 PoC

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 174960.

CVE-2020-7352
GOG GalaxyClientService Windows
8.4
HIGH
EPSS
10.7%
2020 CWE-264 2 PoCs

The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embedded, static RSA private key, an attacker with this key material and local user permissions can effectively send any operating system command to the service for execution in this elevated context. The service listens for such commands on a locally-bound network port, localhost:9978. A Metasploit module has been published which exploits this vulnerability. This issue affects the 2.0.x branch of the software (2.0.12 and earlier) as well as the 1.2.x

CVE-2020-7257
McAfee Endpoint Security (ENS) Windows
8.4
HIGH
EPSS
0.1%
2020 CWE-264 1 PoC

Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the deletion and creation of files they would not normally have permission to through altering the target of symbolic links whilst an anti-virus scan was in progress. This is timing dependent.

CVE-2020-37025
Port Forwarding Wizard Windows
8.4
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

Port Forwarding Wizard 4.8.0 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code through a long request in the Register feature. Attackers can craft a malicious payload with an egg tag and overwrite SEH handlers to potentially execute shellcode on vulnerable Windows systems.

CVE-2020-17144
🔥 KEV Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 Windows
8.4
HIGH
EPSS
92.0%
2020 2 PoCs

Microsoft Exchange Remote Code Execution Vulnerability

CVE-2020-16875
Microsoft Exchange Server 2019 Cumulative Update 5 Windows
8.4
HIGH
EPSS
86.8%
2020 1 PoC

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p>

CVE-2020-36730
CMP – Coming Soon & Maintenance Plugin by NiteoThemes Web Windows
8.3
HIGH
EPSS
46.4%
2020 CWE-862 2 PoCs

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.

CVE-2020-15841
Software Genérico Windows
8.3
HIGH
EPSS
0.3%
2020 1 PoC

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.

CVE-2020-7314
McAfee DXL for Mac shipped with MA Windows
8.2
HIGH
EPSS
0.0%
2020 CWE-732 1 PoC

Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.

CVE-2020-7250
McAfee Endpoint Security (ENS) Windows
8.2
HIGH
EPSS
0.1%
2020 CWE-59 1 PoC

Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an escalation of privileges by pointing the link to files which the user which not normally have permission to alter via carefully creating symbolic links from the ENS log file directory.

CVE-2020-36659
Software Genérico Web Windows
8.1
HIGH
EPSS
0.3%
2020 1 PoC

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

CVE-2020-0601
🔥 KEV Windows Web Windows
8.1
HIGH
EPSS
94.1%
2020 23 PoCs

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

CVE-2020-36658
Software Genérico Web Windows
8.1
HIGH
EPSS
0.2%
2020 1 PoC

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

CVE-2020-36836
WP Fastest Cache – WordPress Cache Plugin Web Windows ⚡ nuclei
8.0
HIGH
EPSS
43.1%
2020 CWE-352 0 PoCs

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.

CVE-2020-15261
veyon Windows
8.0
HIGH
EPSS
8.1%
2020 CWE-428 4 PoCs

On Windows the Veyon Service before version 4.4.2 contains an unquoted service path vulnerability, allowing locally authenticated users with administrative privileges to run malicious executables with LocalSystem privileges. Since Veyon users (both students and teachers) usually don't have administrative privileges, this vulnerability is only dangerous in anyway unsafe setups. The problem has been fixed in version 4.4.2. As a workaround, the exploitation of the vulnerability can be prevented by revoking administrative privileges from all potentially untrustworthy users.

CVE-2020-14878
MySQL Server Database Windows
8.0
HIGH
EPSS
0.9%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-16939
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
19.9%
2020 1 PoC

<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.</p> <p>The security update addresses the vulnerability by correcting how Group Policy checks access.</p>