Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-38193 Unspecified vulnerability in Microsoft products
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2024-08-13 CVE-2024-38195 Unspecified vulnerability in Microsoft Azure Cyclecloud
Azure CycleCloud Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2024-08-13 CVE-2024-38196 Unspecified vulnerability in Microsoft products
Windows Common Log File System Driver Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2024-08-13 CVE-2024-38198 Unspecified vulnerability in Microsoft products
Windows Print Spooler Elevation of Privilege Vulnerability
network
high complexity
microsoft
7.5
2024-08-13 CVE-2024-38201 Unspecified vulnerability in Microsoft Azure Stack HUB
Azure Stack Hub Elevation of Privilege Vulnerability
local
high complexity
microsoft
7.0
2024-08-13 CVE-2024-38211 Cross-site Scripting vulnerability in Microsoft Dynamics 365 9.1
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
network
low complexity
microsoft CWE-79
8.2
2024-08-13 CVE-2024-38215 Unspecified vulnerability in Microsoft products
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2024-08-08 CVE-2024-38202 Unspecified vulnerability in Microsoft products
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS).
local
low complexity
microsoft
7.3
2024-07-23 CVE-2024-38164 Improper Access Control vulnerability in Microsoft Groupme
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
network
low complexity
microsoft CWE-284
8.8
2024-07-23 CVE-2024-38176 Improper Restriction of Excessive Authentication Attempts vulnerability in Microsoft Groupme
An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.
network
high complexity
microsoft CWE-307
8.1