KEV category
Windows KEV entries for small business
KEV entries affecting Microsoft Windows — the operating system your workstations and servers run, where your line-of-business software (accounting, document management, practice management) lives. Exploitation gives an attacker access to that machine: client files, stored credentials, and the local network it's on. Updated daily from the CISA KEV catalog.
CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSockUse-After-Free VulnerabilityPlan to patchAdded to KEV Aug 11, 2026
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2008-4250 · Microsoft WindowsBuffer Overflow VulnerabilityPatch this weekAdded to KEV May 20, 2026
Microsoft Windows Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CVE-2026-32202 · Microsoft WindowsProtection Mechanism Failure VulnerabilityMonitorAdded to KEV Apr 28, 2026
Microsoft Windows Protection Mechanism Failure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
- KB5082123
- KB5082142
- KB5082200
- KB5082063
- +7 more
Microsoft Windows: 2 CVEsPlan to patchadded Apr 13, 2026
Microsoft Windows Link Following Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
- KB5072033
- KB5072014
Microsoft Windows Out-of-Bounds Read Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
- KB5032190
- KB5032202
- KB5032196
- KB5032198
- +11 more
CVE-2008-0015 · Microsoft WindowsVideo ActiveX Control Remote Code Execution VulnerabilityPlan to patchAdded to KEV Feb 17, 2026
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
Microsoft Windows: 5 CVEsPlan to patchadded Feb 10, 2026
Microsoft Windows Type Confusion Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
- KB5075904
- KB5075906
- KB5075943
- KB5075912
- +8 more
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
- KB5077179
- KB5075904
- KB5075906
- KB5075943
- +10 more
Microsoft Windows Improper Privilege Management Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
- KB5077179
- KB5075904
- KB5075906
- KB5075943
- +10 more
Microsoft Windows NULL Pointer Dereference Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
- KB5075904
- KB5075906
- KB5075943
- KB5075912
- +10 more
Microsoft Windows Shell Protection Mechanism Failure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
- KB5075904
- KB5075906
- KB5075943
- KB5075912
- +10 more
CVE-2026-20805 · Microsoft WindowsInformation Disclosure VulnerabilityMonitorAdded to KEV Jan 13, 2026
Microsoft Windows Information Disclosure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
- KB5073723
- KB5073457
- KB5073724
- KB5073379
- +6 more
CVE-2025-62221 · Microsoft WindowsUse After Free VulnerabilityPlan to patchAdded to KEV Dec 9, 2025
Microsoft Windows Use After Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
- KB5071544
- KB5071546
- KB5072033
- KB5072014
- +4 more
CVE-2025-62215 · Microsoft WindowsRace Condition VulnerabilityPlan to patchAdded to KEV Nov 12, 2025
Microsoft Windows Race Condition Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.
- KB5068791
- KB5068787
- KB5068840
- KB5068781
- +4 more
CVE-2025-59287 · Microsoft WindowsServer Update Service (WSUS) Deserialization of Untrusted Data VulnerabilityPatch this weekAdded to KEV Oct 24, 2025
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
- KB5070883
- KB5070884
- KB5070892
- KB5070881
- +5 more
CVE-2025-33073 · Microsoft WindowsSMB Client Improper Access Control VulnerabilityPlan to patchAdded to KEV Oct 20, 2025
Microsoft Windows SMB Client Improper Access Control Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.
- KB5060531
- KB5060526
- KB5060525
- KB5060533
- +12 more
Microsoft Windows: 2 CVEsPlan to patchadded Oct 14, 2025
Microsoft Windows Untrusted Pointer Dereference Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.
- KB5066835
- KB5066586
- KB5066782
- KB5066791
- +10 more
Microsoft Windows Improper Access Control Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
- KB5066586
- KB5066782
- KB5066791
- KB5066793
- +10 more
Microsoft Windows: 3 CVEsPlan to patchadded Oct 6, 2025
Microsoft Windows Out-of-Bounds Write Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
- KB5008218
- KB5008206
- KB5008212
- KB5008223
- +11 more
Microsoft Windows Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.
CVE-2025-33053 · Microsoft WindowsExternal Control of File Name or Path VulnerabilityPlan to patchAdded to KEV Jun 10, 2025
Microsoft Windows External Control of File Name or Path Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.
- KB5060531
- KB5060526
- KB5060525
- KB5060533
- +11 more
Microsoft Windows: 5 CVEsPlan to patchadded May 13, 2025
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.
- KB5058392
- KB5058385
- KB5058500
- KB5058379
- +12 more
Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5058392
- KB5058385
- KB5058500
- KB5058379
- +12 more
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5058392
- KB5058385
- KB5058500
- KB5058379
- +12 more
Microsoft Windows DWM Core Library Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5058392
- KB5058385
- KB5058500
- KB5058379
- +4 more
Microsoft Windows Scripting Engine Type Confusion Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.
- KB5058392
- KB5058385
- KB5058500
- KB5058379
- +13 more
CVE-2025-24054 · Microsoft WindowsNTLM Hash Disclosure Spoofing VulnerabilityMonitorAdded to KEV Apr 17, 2025
Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +10 more
CVE-2025-29824 · Microsoft WindowsCommon Log File System (CLFS) Driver Use-After-Free VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 8, 2025
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5055519
- KB5055526
- KB5055518
- KB5055528
- +10 more
Microsoft Windows: 6 CVEsPatch nowadded Mar 11, 2025
- CVE-2025-26633Known ransomware use
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +12 more
Microsoft Windows NTFS Information Disclosure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +8 more
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +12 more
Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +12 more
Microsoft Windows Win32k Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5053618
- KB5053594
- KB5053888
- KB5053995
- +4 more
Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +12 more
CVE-2018-8639 · Microsoft WindowsWin32k Improper Resource Shutdown or Release VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 3, 2025
Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
- KB4471327
- KB4471324
- KB4471329
- KB4471323
- +10 more
Microsoft Windows: 2 CVEsPlan to patchadded Feb 11, 2025
Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
- KB5052000
- KB5051979
- KB5052106
- KB5051974
- +12 more
Microsoft Windows Storage Link Following Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.
- KB5052000
- KB5051979
- KB5052106
- KB5051974
- +6 more
Microsoft Windows: 3 CVEsPlan to patchadded Jan 14, 2025
Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
- KB5049981
- KB5050021
- KB5050009
- KB5049984
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
- KB5049981
- KB5050021
- KB5050009
- KB5049984
Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
- KB5049981
- KB5050021
- KB5050009
- KB5049984
CVE-2024-35250 · Microsoft WindowsKernel-Mode Driver Untrusted Pointer Dereference VulnerabilityPlan to patchAdded to KEV Dec 16, 2024
Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
- KB5039217
- KB5039227
- KB5039330
- KB5039213
- +11 more
CVE-2024-49138 · Microsoft WindowsCommon Log File System (CLFS) Driver Heap-Based Buffer Overflow VulnerabilityPlan to patchAdded to KEV Dec 10, 2024
Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
- KB5048661
- KB5048654
- KB5048800
- KB5048652
- +12 more
Microsoft Windows: 2 CVEsPatch nowadded Nov 12, 2024
- CVE-2024-49039Known ransomware use
Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.
- KB5046617
- KB5046696
- KB5046615
- KB5046616
- +6 more
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.
- KB5046617
- KB5046696
- KB5046615
- KB5046616
- +12 more
CVE-2024-30088 · Microsoft WindowsKernel TOCTOU Race Condition VulnerabilityKnown ransomware usePatch nowAdded to KEV Oct 15, 2024
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
- KB5039217
- KB5039227
- KB5039330
- KB5039213
- +5 more
Microsoft Windows: 2 CVEsPlan to patchadded Oct 8, 2024
Microsoft Windows Management Console Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.
- KB5044277
- KB5044281
- KB5044280
- KB5044273
- +11 more
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.
- KB5044273
- KB5044280
- KB5044285
- KB5044281
- +6 more
CVE-2024-43461 · Microsoft WindowsMSHTML Platform Spoofing VulnerabilityPlan to patchAdded to KEV Sep 16, 2024
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112.
- KB5043080
- KB5043050
- KB5042881
- KB5042880
- +12 more
Microsoft Windows: 2 CVEsPlan to patchadded Sep 10, 2024
Microsoft Windows Installer Improper Privilege Management Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
- KB5043050
- KB5042881
- KB5042880
- KB5043067
- +12 more
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
- KB5043050
- KB5042881
- KB5042880
- KB5043067
- +12 more
Microsoft Windows: 5 CVEsPlan to patchadded Aug 13, 2024
Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.
- KB5041578
- KB5041160
- KB5041592
- KB5041580
- +7 more
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.
- KB5041571
- KB5041578
- KB5041160
- KB5041592
- +7 more
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
- KB5039217
- KB5039227
- KB5039330
- KB5039213
- +7 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition.
- KB5041578
- KB5041160
- KB5041592
- KB5041580
- +5 more
Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
- KB5041571
- KB5041578
- KB5041160
- KB5041592
- +11 more
CVE-2018-0824 · Microsoft WindowsCOM for Windows Deserialization of Untrusted Data VulnerabilityPlan to patchAdded to KEV Aug 5, 2024
Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
- KB4103721
- KB4103727
- KB4103731
- KB4103716
- +8 more
CVE-2024-38112 · Microsoft WindowsMSHTML Platform Spoofing VulnerabilityPlan to patchAdded to KEV Jul 9, 2024
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.
- KB5040427
- KB5040442
- KB5040448
- KB5040434
- +8 more
CVE-2024-38080 · Microsoft WindowsHyper-V Privilege Escalation VulnerabilityPlan to patchAdded to KEV Jul 9, 2024
Microsoft Windows Hyper-V Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
- KB5040437
- KB5040431
- KB5040442
- KB5040438
CVE-2024-26169 · Microsoft WindowsError Reporting Service Improper Privilege Management VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 13, 2024
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
- KB5035849
- KB5035857
- KB5035959
- KB5035854
- +6 more
CVE-2024-30040 · Microsoft WindowsMSHTML Platform Security Feature Bypass VulnerabilityPlan to patchAdded to KEV May 14, 2024
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
- KB5037765
- KB5037782
- KB5037848
- KB5037770
- +5 more
CVE-2022-38028 · Microsoft WindowsPrint Spooler Privilege Escalation VulnerabilityPlan to patchAdded to KEV Apr 23, 2024
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
- KB5018419
- KB5018410
- KB5018421
- KB5018418
- +7 more
CVE-2024-21338 · Microsoft WindowsKernel Exposed IOCTL with Insufficient Access Control VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 4, 2024
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.
- KB5034768
- KB5034770
- KB5034766
- KB5034763
- +2 more
Microsoft Windows: 2 CVEsPatch nowadded Feb 13, 2024
- CVE-2024-21412Known ransomware use
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
- KB5034766
- KB5034768
- KB5034763
- KB5034770
- +2 more
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.
- KB5034765
- KB5034768
- KB5034770
- KB5034766
- +3 more
CVE-2023-36584 · Microsoft WindowsMark of the Web (MOTW) Security Feature Bypass VulnerabilityMonitorAdded to KEV Nov 16, 2023
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
- KB5031361
- KB5031364
- KB5031358
- KB5031356
- +11 more
Microsoft Windows: 3 CVEsPlan to patchadded Nov 14, 2023
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
- KB5032196
- KB5032198
- KB5032304
- KB5032192
- +3 more
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
- KB5032196
- KB5032198
- KB5032304
- KB5032192
- +11 more
Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.
- KB5032196
- KB5032198
- KB5032304
- KB5032192
- +11 more
CVE-2023-28229 · Microsoft Windows CNG Key Isolation ServicePrivilege Escalation VulnerabilityPlan to patchAdded to KEV Oct 4, 2023
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
- KB5025229
- KB5025230
- KB5025221
- KB5025224
- +11 more
CVE-2023-36884 · Microsoft WindowsSearch Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 17, 2023
Microsoft Windows Search Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
- KB5029247
- KB5029250
- KB5029367
- KB5029253
- +12 more
Microsoft Windows: 3 CVEsPlan to patchadded Jul 11, 2023
Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.
- KB5028168
- KB5028171
- KB5028182
- KB5028166
- +10 more
Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.
- KB5028168
- KB5028171
- KB5028182
- KB5028166
- +12 more
Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.
- KB5028168
- KB5028171
- KB5028182
- KB5028166
- +2 more
CVE-2023-28252 · Microsoft WindowsCommon Log File System (CLFS) Driver Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 11, 2023
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5025229
- KB5025230
- KB5025221
- KB5025224
- +11 more
CVE-2019-1388 · Microsoft WindowsCertificate Dialog Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 7, 2023
Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
- KB4525237
- KB4523205
- KB4525241
- KB4524570
- +10 more
CVE-2023-24880 · Microsoft WindowsSmartScreen Security Feature Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 14, 2023
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
- KB5023702
- KB5023705
- KB5023786
- KB5023696
- +3 more
Microsoft Windows: 2 CVEsPatch nowadded Feb 14, 2023
Microsoft Windows Graphic Component Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
- KB5022840
- KB5022842
- KB5022921
- KB5022834
- +12 more
- CVE-2023-23376Known ransomware use
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5022840
- KB5022842
- KB5022921
- KB5022834
- +12 more
CVE-2023-21674 · Microsoft WindowsAdvanced Local Procedure Call (ALPC) Privilege Escalation VulnerabilityPlan to patchAdded to KEV Jan 10, 2023
Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
- KB5022286
- KB5022291
- KB5022282
- KB5022287
- +5 more
CVE-2022-41049 · Microsoft WindowsMark of the Web (MOTW) Security Feature Bypass VulnerabilityMonitorAdded to KEV Nov 14, 2022
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +4 more
Microsoft Windows: 4 CVEsPatch nowadded Nov 8, 2022
Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +11 more
- CVE-2022-41073Known ransomware use
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +12 more
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +8 more
- CVE-2022-41091Known ransomware use
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +4 more
CVE-2022-41033 · Microsoft Windows COM+ Event System ServicePrivilege Escalation VulnerabilityPlan to patchAdded to KEV Oct 11, 2022
Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
- KB5018419
- KB5018410
- KB5018421
- KB5018418
- +11 more
CVE-2010-2568 · Microsoft WindowsRemote Code Execution VulnerabilityPlan to patchAdded to KEV Sep 15, 2022
Microsoft Windows Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.
CVE-2022-37969 · Microsoft WindowsCommon Log File System (CLFS) Driver Privilege Escalation VulnerabilityPlan to patchAdded to KEV Sep 14, 2022
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5017315
- KB5017308
- KB5017316
- KB5017392
- +11 more
CVE-2022-21971 · Microsoft WindowsRuntime Remote Code Execution VulnerabilityPlan to patchAdded to KEV Aug 18, 2022
Microsoft Windows Runtime Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
- KB5010351
- KB5010345
- KB5010342
- KB5010354
- +2 more
CVE-2022-34713 · Microsoft WindowsSupport Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityPlan to patchAdded to KEV Aug 9, 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.
- KB5016623
- KB5016616
- KB5016627
- KB5016629
- +8 more
CVE-2022-22047 · Microsoft WindowsClient Server Runtime Subsystem (CSRSS) Privilege Escalation VulnerabilityPlan to patchAdded to KEV Jul 12, 2022
Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
- KB5015811
- KB5015807
- KB5015827
- KB5015814
- +10 more
CVE-2022-26925 · Microsoft WindowsLSA Spoofing VulnerabilityPlan to patchAdded to KEV Jul 1, 2022
Microsoft Windows LSA Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
- KB5013941
- KB5013945
- KB5013942
- KB5013944
- +12 more
CVE-2022-30190 · Microsoft WindowsSupport Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 14, 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
- KB5014692
- KB5014699
- KB5014678
- KB5014697
- +8 more
CVE-2012-0151 · Microsoft WindowsAuthenticode Signature Verification Remote Code Execution VulnerabilityPlan to patchAdded to KEV Jun 8, 2022
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
Microsoft Windows: 7 CVEsPlan to patchadded May 25, 2022
Microsoft Windows Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
Microsoft Windows Mount Manager Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.
- KB3200970
- KB3198585
- KB3198586
- KB3197868
- +6 more
Microsoft Windows Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
Microsoft Windows TS WebProxy Directory Traversal Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
Microsoft Windows: 3 CVEsPatch this weekadded May 24, 2022
Microsoft Windows Search Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
- KB4022727
- KB4022714
- KB4025339
- KB4025342
- +7 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
- KB4471327
- KB4471324
- KB4471332
- KB4471329
- +10 more
Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
- KB4013429
- KB4012606
- KB4013198
- KB4012215
- +6 more
Microsoft Windows: 5 CVEsPatch nowadded May 23, 2022
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.
- KB4507450
- KB4507435
- KB4507469
- KB4507455
- +7 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
- KB4550922
- KB4549949
- KB4549951
- KB4550927
- +10 more
- CVE-2019-1385Known ransomware use
Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
- KB4525237
- KB4523205
- KB4525241
- KB4524570
- CVE-2019-1130Known ransomware use
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
- KB4507450
- KB4507435
- KB4507469
- KB4507455
- +7 more
Microsoft Windows SMB Information Disclosure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
- KB4489871
- KB4489868
- KB4489886
- KB4489872
- +10 more
Microsoft Windows: 2 CVEsPlan to patchadded Apr 25, 2022
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
- KB5009557
- KB5009545
- KB5009543
- KB5009555
- +11 more
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
- KB5012647
- KB5012591
- KB5012599
- KB5012604
- +11 more
CVE-2022-22718 · Microsoft WindowsPrint Spooler Privilege Escalation VulnerabilityPlan to patchAdded to KEV Apr 19, 2022
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
- KB5010351
- KB5010345
- KB5010342
- KB5010354
- +12 more
CVE-2022-24521 · Microsoft WindowsCLFS Driver Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 13, 2022
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5012647
- KB5012591
- KB5012599
- KB5012604
- +11 more
CVE-2021-34484 · Microsoft WindowsUser Profile Service Privilege Escalation VulnerabilityPlan to patchAdded to KEV Mar 31, 2022
Microsoft Windows User Profile Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
- KB5005030
- KB5005031
- KB5005033
- KB5005040
- +9 more
Microsoft Windows: 6 CVEsPatch nowadded Mar 28, 2022
- CVE-2018-8440Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
- KB4457138
- KB4457128
- KB4457142
- KB4457132
- +9 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
- CVE-2017-0213Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
- KB4019474
- KB4019473
- KB4019472
- KB4019264
- +7 more
Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
Microsoft Windows Event Tracing Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
- KB5005030
- KB5005031
- KB5005033
Microsoft Windows: 4 CVEsPatch nowadded Mar 25, 2022
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
Microsoft Windows Shell Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
- KB4343885
- KB4343909
- KB4343897
- CVE-2022-21999Known ransomware use
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
- KB5010351
- KB5010345
- KB5010342
- KB5010354
- +12 more
- CVE-2017-0146Known ransomware use
Microsoft Windows SMB Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
Microsoft Windows: 10 CVEsPatch nowadded Mar 15, 2022
- CVE-2017-0101Known ransomware use
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
- KB4012215
- KB4012212
- KB4011981
- CVE-2019-0543Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4480973
- KB4480966
- KB4480116
- KB4480978
- +10 more
- CVE-2019-1064Known ransomware use
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4503279
- KB4503286
- KB4503327
- KB4503284
- +2 more
- CVE-2019-0841Known ransomware use
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4493474
- KB4493464
- KB4493509
- KB4493441
- CVE-2019-1315Known ransomware use
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
- KB4520010
- KB4520008
- KB4519338
- KB4520004
- +11 more
- CVE-2019-1129Known ransomware use
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4507450
- KB4507435
- KB4507469
- KB4507455
- +1 more
- CVE-2016-3309Known ransomware use
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
- KB3177725
- KB3176492
- KB3176493
- KB3176495
- CVE-2019-1405Known ransomware use
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
- KB4525237
- KB4523205
- KB4525241
- KB4524570
- +10 more
- CVE-2019-1322Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4517389
- KB4520008
- KB4519338
- CVE-2019-1253Known ransomware use
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
- KB4516068
- KB4516058
- KB4512578
- KB4516066
- +1 more
Microsoft Windows: 8 CVEsPatch nowadded Mar 3, 2022
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.
Microsoft Windows Kernel Exception Handler Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
Microsoft Windows Improper Input Validation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.
- CVE-2021-41379Known ransomware use
Microsoft Windows Installer Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
- KB5007206
- KB5007189
- KB5007186
- KB5007205
- +11 more
- CVE-2016-0099Known ransomware use
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.
CVE-2014-6352 · Microsoft WindowsCode Injection VulnerabilityPlan to patchAdded to KEV Feb 25, 2022
Microsoft Windows Code Injection Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
CVE-2018-8174 · Microsoft WindowsVBScript Engine Out-of-Bounds Write VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 15, 2022
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
- KB4103727
- KB4103731
- KB4103721
- KB4103716
- +8 more
Microsoft Windows: 2 CVEsPlan to patchadded Feb 10, 2022
Microsoft Windows SAM Local Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
- KB5005030
- KB5005031
- KB5005033
Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
- KB4022727
- KB4022714
- KB4022715
- KB4022725
- +7 more
CVE-2020-0787 · Microsoft WindowsBackground Intelligent Transfer Service (BITS) Improper Privilege Management VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 28, 2022
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
- KB4540689
- KB4538461
- KB4540673
- KB4540681
- +10 more
CVE-2021-43890 · Microsoft WindowsAppX Installer Spoofing VulnerabilityKnown ransomware usePatch nowAdded to KEV Dec 15, 2021
Microsoft Windows AppX Installer Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
CVE-2021-40449 · Microsoft WindowsWin32k Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 17, 2021
Microsoft Windows Win32k Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Unspecified vulnerability allows for an authenticated user to escalate privileges.
- KB5006672
- KB5006667
- KB5006670
- KB5006699
- +11 more
Microsoft Windows: 26 CVEsPatch nowadded Nov 3, 2021
Microsoft Windows CryptoAPI Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
- KB4534293
- KB4534273
- KB4534276
- KB4528760
- +2 more
Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
- KB5003635
- KB5003637
- CVE-2014-1812Known ransomware use
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
Microsoft Windows Kernel Information Disclosure Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.
- KB5003646
- KB5003635
- KB5003637
Microsoft Windows Media Center Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.
Microsoft Windows Installer Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.
- KB4537762
- KB4532691
- KB4537789
- KB4532693
- +10 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
- KB4586785
- KB4586793
- KB4586786
- KB4586781
- +10 more
Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
- KB5003646
- KB5003635
- KB5003637
- KB5003687
- +6 more
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
- KB4558998
- KB4565483
- KB4565503
- KB4565511
- +8 more
- CVE-2019-1215Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.
- KB4516068
- KB4516058
- KB4512578
- KB4516066
- +11 more
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
- KB5004244
- KB5004245
- KB5004237
- KB5004249
- +5 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
- KB5004244
- KB5004245
- KB5004237
- KB5004249
- +3 more
Microsoft Windows NTFS Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.
- KB5003646
- KB5003635
- KB5003637
- KB5003687
- +9 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
- KB5004244
- KB5004245
- KB5004237
- KB5004249
- +9 more
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode.
- KB4561621
- KB4561608
- KB4560960
- KB4556799
- +8 more
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
- KB4550922
- KB4549949
- KB4549951
- KB4550927
- +10 more
Microsoft Windows Update Medic Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
- KB5005030
- KB5005031
- KB5005033
- CVE-2017-0143Known ransomware use
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
- KB4550922
- KB4549949
- KB4549951
- KB4550927
- +10 more
Microsoft Windows Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
- KB4571709
- KB4565349
- KB4565351
- KB4571741
- +11 more
- CVE-2021-36955Known ransomware use
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5005568
- KB5005566
- KB5005565
- KB5005575
- +10 more
- CVE-2021-34527Known ransomware use
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
- KB5004947
- KB5005575
- KB5004945
- KB5007215
- +13 more
- CVE-2021-36942Known ransomware use
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.
- KB5005030
- KB5005033
- KB5005043
- KB5005090
- +7 more
- CVE-2021-1675Known ransomware use
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
- KB5003646
- KB5003635
- KB5003637
- KB5003687
- +9 more
Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.
- KB4516068
- KB4516058
- KB4512578
- KB4516066
- +11 more
Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
- KB4499181
- KB4499167
- KB4494441
- KB4499179
- +9 more
