Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-49147 Deserialization of Untrusted Data vulnerability in Microsoft Update Catalog
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
network
low complexity
microsoft CWE-502
critical
9.8
2024-11-26 CVE-2024-49035 Unspecified vulnerability in Microsoft Partner Center
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
network
low complexity
microsoft
critical
9.8
2024-11-26 CVE-2024-49038 Unspecified vulnerability in Microsoft Copilot Studio
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
network
low complexity
microsoft
critical
9.6
2024-11-12 CVE-2024-43498 Unspecified vulnerability in Microsoft .Net and Visual Studio 2022
.NET and Visual Studio Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.8
2024-11-12 CVE-2024-43602 Unspecified vulnerability in Microsoft Azure Cyclecloud
Azure CycleCloud Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.9
2024-11-12 CVE-2024-43639 Unspecified vulnerability in Microsoft products
Windows KDC Proxy Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.8
2024-10-17 CVE-2024-43566 Unspecified vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.8
2024-10-08 CVE-2024-38124 Unspecified vulnerability in Microsoft products
Windows Netlogon Elevation of Privilege Vulnerability
low complexity
microsoft
critical
9.0
2024-10-08 CVE-2024-43488 Unspecified vulnerability in Microsoft Visual Studio Code
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
network
low complexity
microsoft
critical
9.8
2024-10-08 CVE-2024-43591 Unspecified vulnerability in Microsoft Azure CLI and Azure Service Connector
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.1