11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-49019
Windows Server 2019 Windows
7.8
HIGH
EPSS
4.8%
2024 CWE-1390 1 PoC

Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2025-53841
Guardicore Platform Agent Windows
7.8
HIGH
EPSS
0.0%
2025 CWE-829 1 PoC

The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to. This allows an unprivileged local user to create a crafted "openssl.cnf" file in that location and, by specifying the path to a custom DLL file in a custom OpenSSL engine definition, execute arbitrary commands with the privileges of the Guardicore

CVE-2022-24481
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
24.9%
2022 2 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-35357
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-125 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-42051
Software Genérico Windows
7.8
HIGH
EPSS
0.0%
2024 1 PoC

The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.

CVE-2022-41975
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.

CVE-2023-49694
NETGEAR ProSAFE Network Management System Web Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.

CVE-2023-33990
SAP SQL Anywhere Database Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an attacker to perform a Denial of Service. Further, an attacker might be able to modify sensitive data in shared memory objects.This issue only affects SAP SQL Anywhere on Windows. Other platforms are not impacted.

CVE-2009-4324
🔥 KEV Software Genérico Web Windows
7.8
HIGH
EPSS
92.9%
2009 2 PoCs

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

CVE-2024-23774
Software Genérico Windows
7.8
HIGH
EPSS
0.5%
2024 1 PoC

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KSchedulerSvc.exe and AMPTools.exe components. This allows local attackers to execute code of their choice with NT Authority\SYSTEM privileges.

CVE-2022-22031
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability

CVE-2023-21772
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-125 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-8895
Earth Pro Windows
7.8
HIGH
EPSS
0.0%
2020 CWE-427 1 PoC

Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system.

CVE-2011-0676
Software Genérico Windows
7.8
HIGH
EPSS
1.1%
2011 1 PoC

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."

CVE-2023-35359
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-23 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-23420
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2023 CWE-416 2 PoCs

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-31019
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVE-2024-50591
Elefant Software Updater Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-77 2 PoCs

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as "SYSTEM" via Windows Named Pipes.The Elefant Software Updater (ESU) consists of two components. An ESU service which runs as "NT AUTHORITY\SYSTEM" and an ESU tray client which communicates with the service to update or repair the installation and is running with user permission

CVE-2024-0118
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.