Výsledky hledání

zdroj: Microsoft Security× v celém archivu zrušit filtry

2906 karet z 2906 položek · strana 27 z 49 CZ · EN/orig

12

ZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56000.

EPSS 0.00 CVSS 7.8 CVE-2026-56000 X.Org Server US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56001.

EPSS 0.00 CVSS 7.8 CVE-2026-56001 X.Org US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56002.

EPSS 0.00 CVSS 7.8 CVE-2026-56002 X.Org US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-408: X.Org Server ComputeScaledProperties Heap-based Buffer Overflow Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-56003.

EPSS 0.00 CVSS 7.8 CVE-2026-56003 X.Org libXfont2 US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-55999.

EPSS 0.00 CVSS 7.8 CVE-2026-55999 X.Org US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40400.

EPSS 0.01 CVSS 7.8 CVE-2026-40400 Microsoft US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-49805.

EPSS 0.00 CVSS 7.0 CVE-2026-49805 Microsoft US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.

EPSS 0.00 CVSS 7.8 CVE-2026-54129 Microsoft US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.

EPSS 0.00 CVSS 7.8 CVE-2026-50311 Microsoft veřejná správa US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability

This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of Microsoft SharePoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-55126.

EPSS 0.01 CVSS 7.3 CVE-2026-55126 Microsoft US 2 zdrojů

Zero Day Initiative · Microsoft Security

48