Windows Defender For Endpoint
by Microsoft
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21315 | Hig | 0.51 | 7.8 | 0.01 | Feb 13, 2024 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | ||
| CVE-2024-49071 | Med | 0.42 | 6.5 | 0.01 | Dec 12, 2024 | Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | ||
| CVE-2022-29799 | Med | 0.37 | 5.5 | 0.12 | Sep 21, 2022 | A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base… | ||
| CVE-2022-29800 | Med | 0.31 | 4.7 | 0.07 | Sep 21, 2022 | A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that… |
- risk 0.51cvss 7.8epss 0.01
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.01
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.5epss 0.12
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base…
- risk 0.31cvss 4.7epss 0.07
A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that…