Vulnerabilities
Vulnerable Software
CVE-2023-24880
Known exploited
Windows SmartScreen Security Feature Bypass Vulnerability
CVSS Score
4.4
EPSS Score
0.773
Published
2023-03-14
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
CVSS Score
7.8
EPSS Score
0.012
Published
2023-02-28
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
CVSS Score
5.5
EPSS Score
0.006
Published
2023-02-28
CVE-2023-21674
Known exploited
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVSS Score
8.8
EPSS Score
0.124
Published
2023-01-10
CVE-2022-44698
Known exploited
Windows SmartScreen Security Feature Bypass Vulnerability
CVSS Score
5.4
EPSS Score
0.664
Published
2022-12-13
CVE-2022-26923
Known exploited
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS Score
8.8
EPSS Score
0.914
Published
2022-05-10
Windows Graphics Component Remote Code Execution Vulnerability
CVSS Score
8.8
EPSS Score
0.285
Published
2021-02-25
Windows LUAFV Elevation of Privilege Vulnerability
CVSS Score
7.3
EPSS Score
0.017
Published
2021-01-12
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVSS Score
7.8
EPSS Score
0.022
Published
2021-01-12
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.
CVSS Score
8.8
EPSS Score
0.154
Published
2020-08-17


Contact Us

Shodan ® - All rights reserved