Windows CSC Service
by Microsoft
CVEs (412)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22042 | Med | 0.42 | 6.5 | 0.03 | Jul 12, 2022 | Windows Hyper-V Information Disclosure Vulnerability | ||
| CVE-2022-29121 | Med | 0.42 | 6.5 | 0.01 | May 10, 2022 | Windows WLAN AutoConfig Service Denial of Service Vulnerability | ||
| CVE-2022-29112 | Med | 0.42 | 6.5 | 0.03 | May 10, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-26936 | Med | 0.42 | 6.5 | 0.03 | May 10, 2022 | Windows Server Service Information Disclosure Vulnerability | ||
| CVE-2022-26935 | Med | 0.42 | 6.5 | 0.01 | May 10, 2022 | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | ||
| CVE-2022-26934 | Med | 0.42 | 6.5 | 0.03 | May 10, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-22015 | Med | 0.42 | 6.5 | 0.02 | May 10, 2022 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | ||
| CVE-2022-24498 | Med | 0.42 | 6.5 | 0.02 | Apr 15, 2022 | Windows iSCSI Target Service Information Disclosure Vulnerability | ||
| CVE-2022-21915 | Med | 0.42 | 6.5 | 0.03 | Jan 11, 2022 | Windows GDI+ Information Disclosure Vulnerability | ||
| CVE-2019-1043 | Med | 0.42 | 6.4 | 0.03 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | ||
| CVE-2019-1053 | Med | 0.41 | 6.3 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require… | ||
| CVE-2019-0986 | Med | 0.41 | 6.3 | 0.02 | Jun 12, 2019 | An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker… | ||
| CVE-2022-22048 | Med | 0.40 | 6.1 | 0.01 | Jul 12, 2022 | BitLocker Security Feature Bypass Vulnerability | ||
| CVE-2022-37985 | Med | 0.39 | 5.5 | 0.39 | Oct 11, 2022 | Windows Graphics Component Information Disclosure Vulnerability | ||
| CVE-2022-35747 | Med | 0.38 | 5.9 | 0.02 | May 31, 2023 | Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | ||
| CVE-2022-41116 | Med | 0.38 | 5.9 | 0.01 | Nov 9, 2022 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | ||
| CVE-2022-41090 | Med | 0.38 | 5.9 | 0.01 | Nov 9, 2022 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | ||
| CVE-2019-1040 | Med | 0.38 | 5.3 | 0.48 | Jun 12, 2019 | A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security… | ||
| CVE-2022-30223 | Med | 0.37 | 5.7 | 0.01 | Jul 12, 2022 | Windows Hyper-V Information Disclosure Vulnerability | ||
| CVE-2022-35758 | Med | 0.36 | 5.5 | 0.01 | May 31, 2023 | Windows Kernel Memory Information Disclosure Vulnerability |
- risk 0.42cvss 6.5epss 0.03
Windows Hyper-V Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows WLAN AutoConfig Service Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Server Service Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows iSCSI Target Service Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows GDI+ Information Disclosure Vulnerability
- risk 0.42cvss 6.4epss 0.03
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
- risk 0.41cvss 6.3epss 0.01
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require…
- risk 0.41cvss 6.3epss 0.02
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker…
- risk 0.40cvss 6.1epss 0.01
BitLocker Security Feature Bypass Vulnerability
- risk 0.39cvss 5.5epss 0.39
Windows Graphics Component Information Disclosure Vulnerability
- risk 0.38cvss 5.9epss 0.02
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
- risk 0.38cvss 5.9epss 0.01
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- risk 0.38cvss 5.9epss 0.01
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- risk 0.38cvss 5.3epss 0.48
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security…
- risk 0.37cvss 5.7epss 0.01
Windows Hyper-V Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Memory Information Disclosure Vulnerability
Page 18 of 21