- EPSS 0.02%
- Veröffentlicht 13.01.2026 17:56:13
- Zuletzt bearbeitet 14.01.2026 20:29:02
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:56:12
- Zuletzt bearbeitet 14.01.2026 20:27:14
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-20812
- EPSS 0.07%
- Veröffentlicht 13.01.2026 17:56:11
- Zuletzt bearbeitet 14.01.2026 20:25:38
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.
- EPSS 0.03%
- Veröffentlicht 13.01.2026 17:56:09
- Zuletzt bearbeitet 14.01.2026 20:10:29
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.
CVE-2026-20805
- EPSS 3.23%
- Veröffentlicht 13.01.2026 17:56:08
- Zuletzt bearbeitet 14.01.2026 13:44:31
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVE-2026-20804
- EPSS 0.04%
- Veröffentlicht 13.01.2026 17:56:07
- Zuletzt bearbeitet 14.01.2026 20:03:08
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
CVE-2026-20962
- EPSS 0.16%
- Veröffentlicht 13.01.2026 17:56:03
- Zuletzt bearbeitet 14.01.2026 19:34:12
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
CVE-2025-62221
- EPSS 3.02%
- Veröffentlicht 09.12.2025 17:56:10
- Zuletzt bearbeitet 10.12.2025 13:48:09
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-64679
- EPSS 0.04%
- Veröffentlicht 09.12.2025 17:56:08
- Zuletzt bearbeitet 12.12.2025 13:35:37
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-64680
- EPSS 0.07%
- Veröffentlicht 09.12.2025 17:56:08
- Zuletzt bearbeitet 12.12.2025 13:31:49
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.