Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Windows 11
Total 598 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-42971 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 9.8 CRITICAL
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2022-42972 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 7.8 HIGH
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2022-42973 2 Microsoft, Schneider-electric 8 Windows 10, Windows 11, Windows 7 and 5 more 2023-02-08 N/A 7.8 HIGH
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)
CVE-2021-43880 1 Microsoft 1 Windows 11 2022-07-12 3.6 LOW 5.5 MEDIUM
Windows Mobile Device Management Elevation of Privilege Vulnerability
CVE-2021-43247 1 Microsoft 5 Windows 10, Windows 11, Windows Server and 2 more 2022-07-12 7.2 HIGH 7.8 HIGH
Windows TCP/IP Driver Elevation of Privilege Vulnerability
CVE-2021-43238 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Remote Access Elevation of Privilege Vulnerability
CVE-2021-43248 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Digital Media Receiver Elevation of Privilege Vulnerability
CVE-2021-43883 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-43233 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-07-12 5.1 MEDIUM 7.5 HIGH
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-43219 1 Microsoft 5 Windows 10, Windows 11, Windows Server and 2 more 2022-07-12 7.8 HIGH 7.5 HIGH
DirectX Graphics Kernel File Denial of Service Vulnerability
CVE-2021-43239 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
CVE-2021-43217 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-07-12 7.5 HIGH 9.8 CRITICAL
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
CVE-2021-43232 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2022-07-12 6.8 MEDIUM 7.8 HIGH
Windows Event Tracing Remote Code Execution Vulnerability
CVE-2021-43240 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2022-07-12 4.6 MEDIUM 7.8 HIGH
NTFS Set Short Name Elevation of Privilege Vulnerability
CVE-2021-43893 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-07-12 6.0 MEDIUM 7.5 HIGH
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
CVE-2021-43228 1 Microsoft 5 Windows 10, Windows 11, Windows Server and 2 more 2022-07-12 7.8 HIGH 7.5 HIGH
SymCrypt Denial of Service Vulnerability
CVE-2022-32230 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2019 2022-06-23 7.8 HIGH 7.5 HIGH
Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in the special case of Windows Domain Controllers, where unauthenticated users can always open named pipes as long as they can establish an SMB session. Typically, after the BSOD, the victim SMBv3 server will reboot.
CVE-2021-43234 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-05-23 6.8 MEDIUM 7.8 HIGH
Windows Fax Service Remote Code Execution Vulnerability