Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-01-14 CVE-2020-0654 Improper Privilege Management vulnerability in Microsoft Onedrive
A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for Android handles sharing links., aka 'Microsoft OneDrive for Android Security Feature Bypass Vulnerability'.
network
low complexity
microsoft CWE-269
6.4
2020-01-14 CVE-2020-0644 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-01-14 CVE-2020-0641 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-01-14 CVE-2020-0638 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-01-14 CVE-2020-0636 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2016
An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-01-14 CVE-2020-0635 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-01-14 CVE-2020-0634 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-01-14 CVE-2020-0633 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-01-14 CVE-2020-0632 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-01-14 CVE-2020-0631 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6