Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2020-07-14 CVE-2020-1481 Unspecified vulnerability in Microsoft Visual Studio Code Eslint Extension
A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2020-07-14 CVE-2020-1469 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft Bond 9.0.1
A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'.
network
low complexity
microsoft CWE-434
7.5
2020-07-14 CVE-2020-1465 Unspecified vulnerability in Microsoft Onedrive
An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft OneDrive Elevation of Privilege Vulnerability'.
local
low complexity
microsoft
7.8
2020-07-14 CVE-2020-1463 Unspecified vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory, aka 'Windows SharedStream Library Elevation of Privilege Vulnerability'.
local
low complexity
microsoft
7.8
2020-07-14 CVE-2020-1461 Unspecified vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
local
low complexity
microsoft
7.1
2020-07-14 CVE-2020-1458 Untrusted Search Path vulnerability in Microsoft 365 Apps
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.
local
low complexity
microsoft CWE-426
7.8
2020-07-14 CVE-2020-1449 Origin Validation Error vulnerability in Microsoft 365 Apps, Office and Project 2016
A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'.
local
low complexity
microsoft CWE-346
7.8
2020-07-14 CVE-2020-1448 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2020-07-14 CVE-2020-1447 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2020-07-14 CVE-2020-1446 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8