Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-11 CVE-2017-8588 Unspecified vulnerability in Microsoft products
Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially crafted files, aka "WordPad Remote Code Execution Vulnerability".
local
high complexity
microsoft
7.0
2017-07-11 CVE-2017-8585 Improper Input Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
network
low complexity
microsoft CWE-20
7.5
2017-07-11 CVE-2017-8584 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2016
Windows 10 1607 and Windows Server 2016 allow an attacker to execute code remotely via a specially crafted WiFi packet aka "HoloLens Remote Code Execution Vulnerability."
high complexity
microsoft
7.5
2017-07-11 CVE-2017-8581 Improper Preservation of Permissions vulnerability in Microsoft products
Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
local
high complexity
microsoft CWE-281
7.0
2017-07-11 CVE-2017-8580 Improper Preservation of Permissions vulnerability in Microsoft products
Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
local
high complexity
microsoft CWE-281
7.0
2017-07-11 CVE-2017-8578 Improper Preservation of Permissions vulnerability in Microsoft products
Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
local
low complexity
microsoft CWE-281
7.8
2017-07-11 CVE-2017-8577 Improper Preservation of Permissions vulnerability in Microsoft products
Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
local
high complexity
microsoft CWE-281
7.0
2017-07-11 CVE-2017-8574 Improper Preservation of Permissions vulnerability in Microsoft Windows 10 and Windows Server 2016
Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability".
local
high complexity
microsoft CWE-281
7.0
2017-07-11 CVE-2017-8573 Improper Preservation of Permissions vulnerability in Microsoft products
Graphics in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability".
local
high complexity
microsoft CWE-281
7.0
2017-07-11 CVE-2017-8570 Unspecified vulnerability in Microsoft Office
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
local
low complexity
microsoft
7.8