Microsoft Exchange Online Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5121000.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Click to Run Release Notes Install KB5002901.
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
Release Notes
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
Release Notes
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5121000. Install KB5120418. Install KB5120386. Install ...
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418.
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000.
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in t...
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
See the Microsoft Security Update Guide for the update that applies to your product.
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Release Notes
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Install KB5121003. Install KB5120994. Install KB5121000.
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
See the Microsoft Security Update Guide for the update that applies to your product.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Release Notes
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Click to Run Release Notes
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.