Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2020-05-21 CVE-2020-1114 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-05-21 CVE-2020-1113 Improper Certificate Validation vulnerability in Microsoft products
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.
network
microsoft CWE-295
critical
9.3
2020-05-21 CVE-2020-1112 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
network
low complexity
microsoft CWE-434
critical
9.0
2020-05-21 CVE-2020-1111 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service, aka 'Windows Clipboard Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-05-21 CVE-2020-1110 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2019
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-05-21 CVE-2020-1109 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2019
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-05-21 CVE-2020-1108 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
network
low complexity
microsoft
7.5
2020-05-21 CVE-2020-1107 Cross-site Scripting vulnerability in Microsoft products
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
microsoft CWE-79
3.5
2020-05-21 CVE-2020-1106 Cross-site Scripting vulnerability in Microsoft products
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
low complexity
microsoft CWE-79
6.1
2020-05-21 CVE-2020-1105 Cross-site Scripting vulnerability in Microsoft Sharepoint Enterprise Server and Sharepoint Server
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
microsoft CWE-79
3.5