CVE Database

Comprehensive vulnerability intelligence with advanced analytics

6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.08%
View Details
7.8

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.06%
View Details
7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_11_24h2
EPSS: 0.04%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.09%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.0

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_server_2022_23h2
EPSS: 0.04%
View Details
5.5

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.05%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.15%
View Details
7.8

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_11_24h2
EPSS: 0.04%
View Details
7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.05%
View Details
8.1

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.17%
View Details
7.5

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_11_24h2
EPSS: 0.07%
View Details
7.4

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.05%
View Details
7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
6.2

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_11_24h2
EPSS: 0.04%
View Details
7.5

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.09%
View Details
7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.08%
View Details
6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.16%
View Details