Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-11 CVE-2017-8467 Improper Preservation of Permissions vulnerability in Microsoft products
Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
local
high complexity
microsoft CWE-281
7.0
2017-07-11 CVE-2017-8463 Unspecified vulnerability in Microsoft products
Windows Shell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it improperly handles executable files and shares during rename operations, aka "Windows Explorer Remote Code Execution Vulnerability".
local
low complexity
microsoft
7.8
2017-07-11 CVE-2017-0243 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
local
low complexity
microsoft CWE-119
7.8
2017-06-29 CVE-2017-8613 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Microsoft Azure Active Directory Connect 1.1.524.0
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."
network
high complexity
microsoft CWE-640
8.1
2017-06-29 CVE-2017-8579 Improper Preservation of Permissions vulnerability in Microsoft Windows 10 and Windows Server 2016
The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability."
local
high complexity
microsoft CWE-281
7.0
2017-06-29 CVE-2017-8576 Improper Initialization vulnerability in Microsoft Windows 10 and Windows Server 2016
The graphics component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability."
local
high complexity
microsoft CWE-665
7.0
2017-06-29 CVE-2017-8558 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption.
local
low complexity
microsoft CWE-119
7.8
2017-06-27 CVE-2014-6354 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Internet Explorer
Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 allows remote attackers to execute arbitrary code.
network
high complexity
microsoft CWE-119
7.5
2017-06-26 CVE-2017-9948 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Skype 7.2/7.35/7.36
A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.
network
low complexity
microsoft CWE-119
8.8
2017-06-22 CVE-2017-0176 Classic Buffer Overflow vulnerability in Microsoft Windows Server 2003 and Windows XP
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.
network
high complexity
microsoft CWE-120
8.1