CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 14, 2025

Microsoft OneNote Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Office OneNote. This issue affects multiple versions of OneNote for Mac, as well as Office LTSC for Mac 2024 and 2021. The vulnerability arises from improper restrictions on file names and resources, allowing for unauthorized code execution.

4.9
Jan 14, 2025

Microsoft Access Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Access. This issue allows an attacker to execute arbitrary code on the affected system.

4.0
Jan 14, 2025

Microsoft SharePoint Server Spoofing Vulnerability

A spoofing vulnerability has been identified in Microsoft SharePoint Server. This vulnerability allows an attacker to impersonate another user, potentially leading to unauthorized access or actions within the SharePoint environment.

3.7
Jan 14, 2025

Microsoft Windows upnphost.dll Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the Windows upnphost.dll component. This issue can lead to a disruption of service, causing applications or services to become unresponsive or unavailable.

6.0
Jan 14, 2025

Microsoft Windows Graphics Component Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Windows Graphics Component. This vulnerability allows an attacker to gain higher privileges on the system.

4.6
Jan 14, 2025

Microsoft Windows CSC Service Elevation of Privilege Vulnerability

A vulnerability has been identified in the Windows CSC Service that allows for elevation of privilege. This issue could be exploited to gain higher-level permissions on the system.

4.9
Jan 14, 2025

Microsoft Windows CSC Service Information Disclosure Vulnerability

A vulnerability allowing information disclosure has been identified in the Windows CSC (Client Side Caching) service. This issue could potentially be exploited to access sensitive information.

4.6
Jan 14, 2025

Microsoft Brokering File System Elevation of Privilege Vulnerability

A use-after-free vulnerability has been identified in the Microsoft Brokering File System, which could allow an attacker to elevate privileges. This vulnerability affects several Microsoft products, including Windows Server 2025, Windows 11 Version 24H2 for x64-based and ARM64-based Systems, and Windows Server 2022, 23H2 Edition (Server Core installation).

4.4
Jan 14, 2025

Microsoft Windows VBS Enclave Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in Windows Virtualization-Based Security (VBS) enclaves. This vulnerability allows an attacker to potentially leak data from the target enclave or execute code within the context of the enclave. The issue affects multiple versions of Windows 11, including 24H2, 23H2, and 22H2, for both x64-based and ARM64-based systems.

1.1
Jan 14, 2025

Microsoft Access Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Access. This issue allows an attacker to execute arbitrary code on the affected system.

4.2
Jan 14, 2025

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in multiple Microsoft Office products, including Microsoft Office LTSC 2024 and Microsoft 365 Apps for Enterprise. This vulnerability allows an attacker to execute arbitrary code on the affected system. The issue arises from an untrusted search path, which can be exploited under certain conditions.

4.9
Jan 14, 2025

Microsoft Excel Security Feature Bypass Vulnerability

A security feature bypass vulnerability has been identified in Microsoft Excel. This vulnerability allows for the circumvention of certain security measures within the application, potentially leading to unauthorized actions or access.

4.7
Jan 14, 2025

Microsoft Word Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Word. This issue is present in several different versions of the application, including Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024 for both 64-bit and 32-bit editions, Microsoft Office LTSC for Mac 2021, and Microsoft 365 Apps for Enterprise for both 64-bit and 32-bit systems. The vulnerability arises from an untrusted pointer dereference, which could potentially allow an attacker to execute arbitrary code on the affected system.

1.6
Jan 14, 2025

Microsoft Excel Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Excel. This issue affects several different versions and stems from a use-after-free flaw, which could be exploited to execute arbitrary code.

4.9
Jan 14, 2025

Microsoft Outlook Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Outlook for Mac, specifically in the Legacy version. This issue allows an attacker to bypass Outlook's protections against certain file extensions, potentially leading to the execution of malicious code. The vulnerability is exploited locally, requiring user interaction, such as previewing an attached file in the attachment Preview Pane.

4.9
Jan 14, 2025

Microsoft AutoUpdate Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in Microsoft AutoUpdate (MAU) for Mac, specifically in version 4.76. This vulnerability allows an attacker to gain elevated privileges, enabling them to execute commands as Root in the target environment.

4.2
Jan 14, 2025

Microsoft Outlook Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in multiple editions of Microsoft Outlook, including Outlook 2016, Office LTSC 2024, Office LTSC 2021, Microsoft 365 Apps for Enterprise, and Office 2019. This vulnerability allows an attacker to execute arbitrary code on the affected system. The issue arises from the use of uninitialized resources, and exploitation requires the victim to open a malicious file. While the vulnerability is classified as remote code execution, it is important to note that the attack must be carried out locally, with the attacker needing access to the victim's Outlook account.

4.7
Jan 14, 2025

Microsoft Office Visio Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office Visio. This issue allows an attacker to execute arbitrary code on the affected system.

3.6
Jan 14, 2025

Microsoft Excel Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Microsoft Excel. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability is present in multiple versions of Microsoft Office, including the 2021 and 2019 LTSC releases, as well as in Microsoft 365 Apps for Enterprise. The root cause of the vulnerability is an untrusted pointer dereference, which can be exploited by manipulating how Excel handles certain types of data.

4.9
Jan 14, 2025

Microsoft SharePoint Server Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft SharePoint Server. This issue allows an attacker to execute arbitrary code on the server where SharePoint is running.

3.8
Jan 14, 2025

Microsoft Office Security Feature Bypass Vulnerability

A security feature bypass vulnerability has been identified in Microsoft Office. This vulnerability allows attackers to bypass certain security mechanisms, potentially leading to unauthorized actions or access within the application.

4.9
Jan 14, 2025

Microsoft Office Visio Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office Visio. This issue allows an attacker to execute arbitrary code on the affected system.

3.7
Jan 14, 2025

Microsoft SharePoint Server Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft SharePoint Server. This issue allows an attacker to execute arbitrary code on the server where SharePoint is running.

4.3
Jan 14, 2025

Microsoft Windows Web Threat Defense User Service Information Disclosure Vulnerability

An information disclosure vulnerability has been identified in the Windows Web Threat Defense User Service. This vulnerability could allow unauthorized users to access sensitive information.

2.5
Jan 14, 2025

Microsoft Windows Digital Media Elevation of Privilege Vulnerability

A vulnerability allowing elevation of privilege has been identified in Windows Digital Media. This issue arises because of an out-of-bounds read, which could potentially be exploited to gain SYSTEM privileges.

4.1
Jan 14, 2025

Microsoft Windows Virtualization-Based Security Feature Bypass Vulnerability

A vulnerability has been identified in Windows Virtualization-Based Security (VBS) that allows for a security feature bypass. This vulnerability could potentially be exploited to undermine the security mechanisms provided by VBS.

1.1
Jan 14, 2025

Microsoft Windows Telephony Service Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in the Windows Telephony Service. This issue allows an attacker to execute arbitrary code on the affected system.

5.5
Jan 14, 2025

Microsoft GDI+ Remote Code Execution Vulnerability

A remote code execution vulnerability in GDI+ has been identified, affecting multiple Microsoft products, including various versions of Microsoft Office for Mac, Windows Server, and Windows 10. The vulnerability allows authenticated attackers to execute arbitrary code on the affected system.

4.8
Jan 14, 2025

Microsoft Windows Cryptographic Information Disclosure Vulnerability

A cryptographic information disclosure vulnerability exists in multiple Windows products, including various Windows Server versions and Windows 10 and 11. This vulnerability allows an attacker to read the contents of encrypted PKCS1 information from a user mode process, potentially leading to unauthorized access to sensitive data.

4.4
Jan 14, 2025

Microsoft Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Windows Hyper-V NT Kernel Integration Virtual Service Provider (VSP). This vulnerability allows an attacker to gain SYSTEM privileges. It exists in various versions of Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025. The issue arises within the Hyper-V NT Kernel Integration VSP, which facilitates communication between the host operating system and container-type virtual machines, such as Windows Sandbox and Microsoft Defender Application Guard. Unlike traditional Hyper-V VMs, which maintain a strong isolation boundary, container-type VMs simulate running on the host, creating a different vulnerability landscape.

6.2
Jan 14, 2025

Microsoft Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Windows Hyper-V NT Kernel Integration Virtual Service Provider (VSP). This vulnerability allows an attacker to gain SYSTEM privileges. It exists in various versions of Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025. The issue arises within the Hyper-V NT Kernel Integration VSP, which facilitates communication between the host operating system and container-type virtual machines, such as Windows Sandbox and Microsoft Defender Application Guard. Unlike traditional Hyper-V VMs, which maintain a strong isolation boundary, container-type VMs simulate running on the host, creating a potential vulnerability.

6.2
Jan 14, 2025

Microsoft Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Windows Hyper-V NT Kernel Integration Virtual Service Provider (VSP). This vulnerability allows an attacker to escalate privileges, potentially gaining SYSTEM rights on the Hyper-V host. The issue arises in container-type virtual machines, such as those used by Windows Sandbox and Microsoft Defender Application Guard, where the Hyper-V NT Kernel Integration VSP driver facilitates communication between the host operating system and the virtual machines. Exploitation of this vulnerability could lead to unauthorized access to sensitive data and a complete takeover of the Hyper-V host.

6.2
Jan 14, 2025

Microsoft Windows MapUrlToZone Security Feature Bypass Vulnerability

A security feature bypass vulnerability has been identified in the MapUrlToZone function across various Microsoft Windows versions. This vulnerability allows for improper resolution of path equivalence, potentially leading to unauthorized actions or access by exploiting the way URLs are mapped to security zones.

4.8
Jan 14, 2025

Microsoft Windows Installer Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Windows Installer. This vulnerability allows an attacker to gain SYSTEM privileges. It requires user interaction, specifically a reboot, to exploit. The issue is present in multiple versions of Windows 10 and Windows 11, as well as Windows Server 2022.

1.1
Jan 14, 2025

Microsoft Windows Remote Desktop Services Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in Windows Remote Desktop Services. This issue allows an attacker to send specially crafted packets that can disrupt the availability of the service, leading to a denial-of-service condition.

5.2
Jan 14, 2025

Microsoft Windows MapUrlToZone Security Feature Bypass Vulnerability

A security feature bypass vulnerability has been identified in Microsoft Windows. This vulnerability allows an attacker to bypass the MapURLToZone method, which could lead to improper handling of security zones. The issue affects all supported versions of Windows, including various server editions. Exploitation requires user interaction, such as opening a specially crafted file.

5.0
Jan 14, 2025

Microsoft Windows MapUrlToZone Security Feature Bypass Vulnerability

A security feature bypass vulnerability has been identified in the MapUrlToZone method across various supported versions of Microsoft Windows. This vulnerability allows an attacker to bypass certain security features, potentially leading to unauthorized access or actions that should be restricted.

4.7
Jan 14, 2025

Microsoft Windows Digital Media Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Windows Digital Media component. This vulnerability allows an attacker to gain higher privileges on the affected system.

4.7
Jan 14, 2025

Microsoft Internet Explorer Remote Code Execution Vulnerability

A remote code execution vulnerability has been identified in Internet Explorer. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability is present in several versions of Internet Explorer and can be exploited locally, requiring user interaction.

4.8
Jan 14, 2025

Microsoft Windows Digital Media Elevation of Privilege Vulnerability

A vulnerability allowing elevation of privilege has been identified in Windows Digital Media. This issue arises from an out-of-bounds read, which could be exploited to gain SYSTEM privileges. The vulnerability affects several versions of Windows, including various editions of Windows 10, Windows 11, Windows Server 2016, and Windows Server 2022, among others.

4.1
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability has been identified in the Windows kernel. This vulnerability could allow an attacker to access certain memory addresses within kernel space, potentially leading to further malicious activities.

4.4
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability in the Windows Kernel has been identified. This vulnerability could allow an attacker to access certain memory addresses within kernel space, potentially leading to further malicious activities.

4.4
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability in the Windows kernel has been identified. This vulnerability could allow an attacker to access certain memory addresses within kernel space, potentially leading to further malicious activities.

4.4
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability in the Windows Kernel has been identified. This vulnerability could allow an attacker to access sensitive information from memory, potentially leading to further exploitation.

4.8
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability in the Windows kernel has been identified. This vulnerability could allow an attacker to access certain memory addresses within kernel space, potentially leading to further malicious activities.

1.1
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability in the Windows Kernel has been identified. This vulnerability could allow an attacker to access sensitive information from memory, potentially leading to further exploitation.

4.8
Jan 14, 2025

Microsoft Windows Kernel Memory Information Disclosure Vulnerability

A memory information disclosure vulnerability has been identified in the Windows kernel. This vulnerability could allow an attacker to access certain memory addresses within kernel space, potentially leading to further malicious activities.

4.4
Jan 14, 2025

Microsoft Brokering File System Elevation of Privilege Vulnerability

An elevation of privilege vulnerability has been identified in the Microsoft Brokering File System. This vulnerability allows an attacker to gain higher privileges than intended, potentially leading to unauthorized actions or access within the system.

1.1
Jan 14, 2025

Microsoft Windows SmartScreen Spoofing Vulnerability

A spoofing vulnerability in Windows SmartScreen has been identified. This issue allows an attacker to manipulate the SmartScreen feature, potentially leading to misleading security warnings or the bypassing of security measures.

2.0
Jan 14, 2025

Microsoft Windows SAM Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the Windows Security Account Manager (SAM). This issue allows an authenticated attacker to make specially crafted API calls that disrupt service, leading to a denial-of-service condition.

4.4