Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.0
Published
2025-09-09
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-09-09
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Scope is changed
CVSS Score
7.7
EPSS Score
0.001
Published
2025-09-09
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.
CVSS Score
6.5
EPSS Score
0.084
Published
2025-09-09
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.
CVSS Score
4.9
EPSS Score
0.002
Published
2025-09-09
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to deny service locally.
CVSS Score
7.0
EPSS Score
0.0
Published
2025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.0
Published
2025-09-09
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
CVSS Score
7.3
EPSS Score
0.0
Published
2025-09-09
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-09-09


Contact Us

Shodan ® - All rights reserved