Windows CSC Service
by Microsoft
CVEs (412)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1014 | Hig | 0.46 | 7.0 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,… | ||
| CVE-2019-0984 | Hig | 0.46 | 7.0 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an… | ||
| CVE-2019-0960 | Hig | 0.46 | 7.0 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,… | ||
| CVE-2023-21563 | Med | 0.44 | 6.8 | 0.02 | Jan 10, 2023 | BitLocker Security Feature Bypass Vulnerability | ||
| CVE-2019-0713 | Med | 0.44 | 6.8 | 0.02 | Jun 12, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,… | ||
| CVE-2023-21560 | Med | 0.43 | 6.6 | 0.01 | Jan 10, 2023 | Windows Boot Manager Security Feature Bypass Vulnerability | ||
| CVE-2022-38032 | Med | 0.43 | 6.6 | 0.01 | Oct 11, 2022 | Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | ||
| CVE-2022-30205 | Med | 0.43 | 6.6 | 0.01 | Jul 12, 2022 | Windows Group Policy Elevation of Privilege Vulnerability | ||
| CVE-2022-22023 | Med | 0.43 | 6.6 | 0.01 | Jul 12, 2022 | Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | ||
| CVE-2019-1025 | Med | 0.43 | 6.5 | 0.05 | Jun 12, 2019 | A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected… | ||
| CVE-2019-0972 | Med | 0.43 | 6.5 | 0.06 | Jun 12, 2019 | This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a… | ||
| CVE-2022-35759 | Med | 0.42 | 6.5 | 0.02 | May 31, 2023 | Windows Local Security Authority (LSA) Denial of Service Vulnerability | ||
| CVE-2022-41097 | Med | 0.42 | 6.5 | 0.01 | Nov 9, 2022 | Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability | ||
| CVE-2022-41086 | Med | 0.42 | 6.4 | 0.00 | Nov 9, 2022 | Windows Group Policy Elevation of Privilege Vulnerability | ||
| CVE-2022-38033 | Med | 0.42 | 6.5 | 0.02 | Oct 11, 2022 | Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability | ||
| CVE-2022-37977 | Med | 0.42 | 6.5 | 0.02 | Oct 11, 2022 | Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | ||
| CVE-2022-35770 | Med | 0.42 | 6.5 | 0.02 | Oct 11, 2022 | Windows NTLM Spoofing Vulnerability | ||
| CVE-2022-38006 | Med | 0.42 | 6.5 | 0.02 | Sep 13, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-35837 | Med | 0.42 | 6.5 | 0.02 | Sep 13, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-30208 | Med | 0.42 | 6.5 | 0.02 | Jul 12, 2022 | Windows Security Account Manager (SAM) Denial of Service Vulnerability |
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an…
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,…
- risk 0.44cvss 6.8epss 0.02
BitLocker Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…
- risk 0.43cvss 6.6epss 0.01
Windows Boot Manager Security Feature Bypass Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows Group Policy Elevation of Privilege Vulnerability
- risk 0.43cvss 6.6epss 0.01
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
- risk 0.43cvss 6.5epss 0.05
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected…
- risk 0.43cvss 6.5epss 0.06
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a…
- risk 0.42cvss 6.5epss 0.02
Windows Local Security Authority (LSA) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
- risk 0.42cvss 6.4epss 0.00
Windows Group Policy Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows NTLM Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Security Account Manager (SAM) Denial of Service Vulnerability
Page 17 of 21