Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2020-05-21 CVE-2020-1068 Unspecified vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft
7.8
2020-05-21 CVE-2020-1067 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2020-05-21 CVE-2020-1066 Unspecified vulnerability in Microsoft .Net Framework 3.0/3.5.1
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level.To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program.The update addresses the vulnerability by correcting how .NET Framework activates COM objects., aka '.NET Framework Elevation of Privilege Vulnerability'.
local
low complexity
microsoft
7.8
2020-05-21 CVE-2020-1065 Out-of-bounds Write vulnerability in Microsoft Chakracore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-05-21 CVE-2020-1064 Unspecified vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.
network
high complexity
microsoft
7.5
2020-05-21 CVE-2020-1062 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-05-21 CVE-2020-1061 Out-of-bounds Write vulnerability in Microsoft products
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-787
8.8
2020-05-21 CVE-2020-1060 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-05-21 CVE-2020-1058 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 11/9
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
network
high complexity
microsoft CWE-787
7.5
2020-05-21 CVE-2020-1056 Unspecified vulnerability in Microsoft Edge
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
network
low complexity
microsoft
8.1