Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.