Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.