CVE Database

Comprehensive vulnerability intelligence with advanced analytics

7.4

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
7.8

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.07%
View Details
7.0

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.05%
View Details
5.5

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
5.5

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_server_2022_23h2
EPSS: 0.05%
View Details
7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.06%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
5.5

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_server_2022_23h2
EPSS: 0.04%
View Details
4.6

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.12%
View Details
5.5

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_server_2022_23h2
EPSS: 0.02%
View Details
7.8

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.06%
View Details
7.8

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
EPSS: 0.04%
View Details
5.5

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.05%
View Details
4.6

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.05%
View Details
5.5

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.05%
View Details
7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
4.4

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_21h2
EPSS: 0.04%
View Details
5.5

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.06%
View Details
5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 15, 2026
Product: microsoft windows_10_1607
EPSS: 0.04%
View Details
7.8

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.04%
View Details
6.2

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.05%
View Details
7.8

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 0.06%
View Details