|
222061
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability,…
|
CWE-59
Link Following
|
CVE-2019-1385
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222062
|
9.9 |
CRITICAL
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted a…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-1384
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222063
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This …
|
NVD-CWE-noinfo
|
CVE-2019-1383
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222064
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper authentication, aka 'Microsoft ActiveX Installer Service Elevation of Privilege …
|
NVD-CWE-noinfo
|
CVE-2019-1382
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222065
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_2019
|
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.
|
CWE-200
Information Exposure
|
CVE-2019-1381
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222066
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-1380
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222067
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2019 windows_10
|
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This …
|
NVD-CWE-noinfo
|
CVE-2019-1379
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222068
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2016 windows_server_2019
|
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'.
|
CWE-200
Information Exposure
|
CVE-2019-1374
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222069
|
9.8 |
CRITICAL
Network
|
microsoft
|
exchange_server
|
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-1373
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222070
|
5.5 |
MEDIUM
Local
|
microsoft
|
open_enclave_software_development_kit
|
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
|
CWE-200
Information Exposure
|
CVE-2019-1370
|
2024-11-21 13:36 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|