Windows Update Stack
by Microsoft
CVEs (17)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21204 | Hig | 0.51 | 7.8 | 0.07 | Apr 8, 2025 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-43530 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2024-38163 | Hig | 0.51 | 7.8 | 0.01 | Aug 14, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2024-26235 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2021-26889 | Hig | 0.51 | 7.8 | 0.01 | Mar 11, 2021 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2020-17077 | Hig | 0.51 | 7.8 | 0.01 | Nov 11, 2020 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2020-1424 | Hig | 0.51 | 7.8 | 0.01 | Jul 14, 2020 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. | ||
| CVE-2020-1110 | Hig | 0.51 | 7.8 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1109. | ||
| CVE-2020-1109 | Hig | 0.51 | 7.8 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1110. | ||
| CVE-2020-0996 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2020 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0985. | ||
| CVE-2020-0985 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2020 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996. | ||
| CVE-2021-1694 | Hig | 0.49 | 7.5 | 0.03 | Jan 12, 2021 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2025-27475 | Hig | 0.46 | 7.0 | 0.00 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-26236 | Hig | 0.46 | 7.0 | 0.00 | Apr 9, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2024-21432 | Hig | 0.46 | 7.0 | 0.01 | Mar 12, 2024 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2022-24525 | Hig | 0.46 | 7.0 | 0.00 | Mar 9, 2022 | Windows Update Stack Elevation of Privilege Vulnerability | ||
| CVE-2021-1729 | Hig | 0.46 | 7.1 | 0.01 | Mar 11, 2021 | Windows Update Stack Setup Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.07
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1109.
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1110.
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0985.
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996.
- risk 0.49cvss 7.5epss 0.03
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Update Stack Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Update Stack Setup Elevation of Privilege Vulnerability