An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function re...
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.