Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.