11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-16939
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
19.9%
2020 1 PoC

<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.</p> <p>The security update addresses the vulnerability by correcting how Group Policy checks access.</p>

CVE-2011-1236
Software Genérico Windows
7.8
HIGH
EPSS
1.1%
2011 1 PoC

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."

CVE-2025-22447
RemoteView Agent (for Windows) Windows
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.

CVE-2009-0082
Software Genérico Windows
7.8
HIGH
EPSS
1.0%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."

CVE-2009-1123
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
5.2%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

CVE-2021-42954
Software Genérico Windows
7.8
HIGH
EPSS
0.0%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.

CVE-2021-26868
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
4.9%
2021 1 PoC

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2023-32046
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
42.7%
2023 1 PoC

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVE-2024-56179
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2024 1 PoC

In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victims' machines via directory traversal if victims opened file attachments located in malicious mmap files.

CVE-2010-2568
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.1%
2010 3 PoCs

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

CVE-2010-0485
Software Genérico Windows
7.8
HIGH
EPSS
1.1%
2010 1 PoC

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."

CVE-2025-55312
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

CVE-2021-42956
Software Genérico Windows
7.8
HIGH
EPSS
0.2%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.

CVE-2021-36934
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
91.0%
2021 16 PoCs

<p>An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>An attacker must have the ability to execute code on a victim system to exploit this vulnerability.</p> <p>After installing this security update, you <em>must</em> manually delete

CVE-2021-28322
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.7%
2021 2 PoCs

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

CVE-2010-4398
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
7.9%
2010 3 PoCs

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."

CVE-2024-0121
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0118
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.