Microsoft

Windows

85 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 08.09.2025 00:00:00
  • Zuletzt bearbeitet 08.09.2025 18:15:34

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. On systems that do not have hypervisor-protected code integrity (HVCI) enabled, entries that specify only the to-be-signed (TBS) part of ...

  • EPSS 0.02%
  • Veröffentlicht 08.09.2025 00:00:00
  • Zuletzt bearbeitet 08.09.2025 16:25:38

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expect...

Medienbericht
  • EPSS 0.35%
  • Veröffentlicht 26.08.2025 16:25:15
  • Zuletzt bearbeitet 03.09.2025 17:31:33

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vul...

  • EPSS 0%
  • Veröffentlicht 02.07.2025 19:25:27
  • Zuletzt bearbeitet 24.07.2025 07:15:53

Rejected reason: Neither filed by Chrome nor a valid security vulnerability.

  • EPSS 0.12%
  • Veröffentlicht 08.04.2025 17:23:36
  • Zuletzt bearbeitet 10.07.2025 15:52:05

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 18.12.2024 23:15:07
  • Zuletzt bearbeitet 26.08.2025 16:09:46

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specia...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 18.12.2024 23:15:07
  • Zuletzt bearbeitet 26.08.2025 16:11:12

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specia...

  • EPSS 0.04%
  • Veröffentlicht 28.05.2024 17:15:10
  • Zuletzt bearbeitet 21.11.2024 09:11:20

Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the macOS resol...

  • EPSS 0.1%
  • Veröffentlicht 27.03.2024 00:15:07
  • Zuletzt bearbeitet 21.11.2024 03:22:50

Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computati...

  • EPSS 0.15%
  • Veröffentlicht 10.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:38:17

A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files bein...