Microsoft Office Graphics Component Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Click to Run Release Notes Install KB5002901.
Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Click to Run Release Notes Install KB5002901.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Click to Run Release Notes Install KB5002901.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Click to Run Install KB5002901.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Install KB5002905. Install KB5002906. Install KB5002894. Install KB5002896. Install KB5002893.
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Install KB5120711. Install KB5120747. Install KB5120702. Install KB5120704. Install KB5120706. Install KB5120703. Install KB5120705. Install KB5120701. Install KB5120698. Install KB5120418. Install KB5120699. Install ...
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Install KB5121003. Install KB5120994.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Install KB5121003. Install KB5120994.
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Install KB5121003. Install KB5120994.
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
Install KB5121003. Install KB5120994. Install KB5121000.
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Release Notes
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
Release Notes
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Click to Run Install KB5002755.
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
Click to Run Install KB5002832.
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Click to Run Release Notes Install KB5002901.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.