Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
The CVSS severity warrants an early asset and exposure review.