Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.