Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-36397 Unspecified vulnerability in Microsoft products
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.8
2023-10-18 CVE-2023-38545 Out-of-bounds Write vulnerability in multiple products
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only.
network
low complexity
haxx fedoraproject netapp microsoft CWE-787
critical
9.8
2023-10-10 CVE-2023-36419 Unspecified vulnerability in Microsoft Azure Hdinsights
Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2023-09-12 CVE-2023-29332 Improper Input Validation vulnerability in Microsoft Azure Kubernetes Service
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
network
low complexity
microsoft CWE-20
critical
9.8
2023-09-12 CVE-2023-36758 Unspecified vulnerability in Microsoft Visual Studio 2022 17.7/17.7.4
Visual Studio Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2023-09-12 CVE-2023-36765 Unspecified vulnerability in Microsoft Office 2019
Microsoft Office Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2023-08-08 CVE-2023-36903 Unspecified vulnerability in Microsoft products
Windows System Assessment Tool Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2023-08-08 CVE-2023-38186 Unspecified vulnerability in Microsoft products
Windows Mobile Device Management Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2023-07-11 CVE-2023-32056 Unspecified vulnerability in Microsoft products
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2023-07-11 CVE-2023-33154 Unspecified vulnerability in Microsoft products
Windows Partition Management Driver Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8