Microsoft security briefs
3328 published alerts for Microsoft products and services.
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21999). Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SMB Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0146). The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1405). A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1322). A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1315). A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1253). A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1129). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Task Scheduler Privilege Escalation Vulnerability
Microsoft Task Scheduler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1069). A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1064). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0841). A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0543). A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8120). A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0101). A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-3309). A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Memory Corruption Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-2546). The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. CISA remediation due date: 2022-04-05. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Installer Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41379). Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2022-03-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8581). A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. CISA remediation due date: 2022-03-17. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0099). A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2015-1701). An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Type Confusion Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0752). A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8174). A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.
Microsoft SMBv3 Remote Code Execution Vulnerability
Microsoft SMBv3 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0796). A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0145). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft SMBv1 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0144). The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.