Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
The CVSS severity warrants an early asset and exposure review.Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
The CVSS severity warrants an early asset and exposure review.Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.