Vulnerabilities > Microsoft > Windows > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-10 CVE-2022-0280 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Microsoft Windows
A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete.
local
high complexity
microsoft CWE-367
7.0
2018-06-26 CVE-2018-0599 Untrusted Search Path vulnerability in Microsoft Windows
Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
microsoft CWE-426
7.8
2018-06-26 CVE-2018-0598 Untrusted Search Path vulnerability in Microsoft Windows
Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
microsoft CWE-426
7.8
2016-06-16 CVE-2016-4158 Permissions, Privileges, and Access Controls vulnerability in multiple products
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
local
low complexity
microsoft adobe CWE-264
7.3