Vulnerabilities > Microsoft > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-28 CVE-2023-1018 Out-of-bounds Read vulnerability in multiple products
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine.
local
low complexity
trustedcomputinggroup microsoft CWE-125
5.5
2023-02-14 CVE-2023-21697 Unspecified vulnerability in Microsoft products
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
local
low complexity
microsoft
5.5
2023-02-14 CVE-2023-23382 Unspecified vulnerability in Microsoft Azure Machine Learning 3.0.0
Azure Machine Learning Compute Instance Information Disclosure Vulnerability
network
low complexity
microsoft
6.5
2022-12-27 CVE-2021-4287 Link Following vulnerability in Microsoft Binwalk
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2.
network
low complexity
microsoft CWE-59
6.5
2022-12-21 CVE-2022-23551 Unspecified vulnerability in Microsoft Azure AD POD Identity
aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022.
local
low complexity
microsoft
5.3
2022-12-13 CVE-2022-41115 Unspecified vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
network
high complexity
microsoft
6.6
2022-11-09 CVE-2022-41049 Unspecified vulnerability in Microsoft products
Windows Mark of the Web Security Feature Bypass Vulnerability
network
low complexity
microsoft
5.4
2022-10-11 CVE-2022-35829 Unspecified vulnerability in Microsoft Azure Service Fabric
Service Fabric Explorer Spoofing Vulnerability
network
low complexity
microsoft
4.8
2022-10-11 CVE-2022-38043 Unspecified vulnerability in Microsoft products
Windows Security Support Provider Interface Information Disclosure Vulnerability
local
low complexity
microsoft
5.5
2022-09-21 CVE-2022-29799 Path Traversal vulnerability in Microsoft Windows Defender for Endpoint
A vulnerability was found in networkd-dispatcher.
local
low complexity
microsoft CWE-22
5.5