Security Vulnerabilities
- CVEs Published In April 2021
Win32k Elevation of Privilege Vulnerability
Windows Media Photo Codec Information Disclosure Vulnerability
Windows Services and Controller App Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
Microsoft Internet Messaging API Remote Code Execution Vulnerability
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
Azure AD Web Sign-in Security Feature Bypass Vulnerability
Windows Kernel Information Disclosure Vulnerability
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to bypass the auth checks. For more details and workaround guidance see the referenced GitHub security advisory.