Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.