privilege escalation

  1. VIDEO CVE-2021-24084 | Windows MDM Local Privilege Escalation Zero Day | Unpatched Since 2020

    :eek:
  2. VIDEO AA21-265A: Conti Ransomware

    Original release date: September 22, 2021 Summary Immediate Actions You Can Take Now to Protect Against Conti Ransomware • Use Link Removed. • Segment and segregate networks and functions. • Update your operating system and software. Note: This Alert uses the MITRE Adversarial Tactics...
  3. AA21-008A: Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments

    Original release date: January 8, 2021 Summary This Advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques. This Alert is a companion alert to Link Removed...
  4. AA20-283A: APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations

    Original release date: October 9, 2020 Summary This joint cybersecurity advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor techniques. Note: the analysis in this joint...
  5. Bountycraft at Nullcon 2017

    Security is a critical component of our products at Microsoft. A strong emphasis on security is a persistent factor throughout our entire development process. Microsoft is committed to designing and developing secure software. Testing is performed both internally and by working closely with the...
  6. MS17-001 - Important: Security Update for Microsoft Edge (3214288) - Version: 1.0

    Severity Rating: Important Revision Note: V1.0 (January 10, 2017): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Edge. This vulnerability could allow elevation of privilege if a user views a specially crafted webpage using Microsoft Edge. An attacker who...
  7. MS16-149 - Important: Security Update for Microsoft Windows (3205655) - Version: 1.0

    Severity Rating: Important Revision Note: V1.0 (December 13, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The most severe of the vulnerabilities could allow elevation of privilege if a locally authenticated attacker runs a specially...
  8. MS16-123 - Important: Security Update for Windows Kernel-Mode Drivers (3192892) - Version: 1.1

    Severity Rating: Important Revision Note: V1.1 (October 11, 2016): Bulletin revised to correct a CVE ID. CVE-2016-7191 has been changed to CVE-2016-7211. This is an informational change only. Customers who have successfully installed the updates do not need to take any further action. Summary...
  9. MS15-104 - Important: Vulnerabilities in Skype for Business Server and Lync Server Could...

    Severity Rating: Important Revision Note: V1.0 (September 8, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Skype for Business Server and Microsoft Lync Server. The most severe of these vulnerabilities could allow elevation of privilege if a user clicks a...
  10. TA15-195A: Adobe Flash and Microsoft Windows Vulnerabilities

    Original release date: July 14, 2015 | Last revised: July 15, 2015 Systems Affected Microsoft Windows systems with Adobe Flash Player installed. Overview Used in conjunction, recently disclosed vulnerabilities in Adobe Flash and Microsoft Windows may allow a remote attacker to execute...
  11. MS15-072 - Important: Vulnerability in Windows Graphics Component Could Allow Elevation of...

    Severity Rating: Important Revision Note: V1.0 (July 14, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if the Windows graphics component fails to properly process bitmap conversions. An...
  12. MS15-063 - Important: Vulnerability in Windows Kernel Could Allow Elevation of Privilege...

    Severity Rating: Important Revision Note: V1.0 (June 9, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker places a malicious .dll file in a local directory on the machine or...
  13. MS15-049 - Important: Vulnerability in Silverlight Could Allow Elevation of Privilege...

    Severity Rating: Important Revision Note: V1.0 (May 12, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Silverlight. The vulnerability could allow elevation of privilege if a specially crafted Silverlight application is run on an affected system. To...
  14. MS15-050: Vulnerability in Service Control Manager could allow elevation of privilege: May...

    Link Removed
  15. TA14-323A: Microsoft Windows Kerberos KDC Remote Privilege Escalation Vulnerability

    Original release date: November 19, 2014 Systems Affected Microsoft Windows Vista, 7, 8, and 8.1 Microsoft Server 2003, Server 2008, Server 2008 R2, Server 2012, and Server 2012 R2 Overview A remote escalation of privilege vulnerability exists in implementations of Kerberos Key Distribution...
  16. MS14-044 - Important: Vulnerabilities in SQL Server Could Allow Elevation of Privilege...

    Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves two privately reported vulnerabilities in Microsoft SQL Server (one in SQL Server Master Data Services and the other in the SQL Server relational database management...
  17. MS13-103 - Important : Vulnerability in ASP.NET SignalR Could Allow Elevation of Privilege...

    Severity Rating: Important Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in ASP.NET SignalR. The vulnerability could allow elevation of privilege if an attacker reflects specially crafted JavaScript back to...
  18. TA13-253A: Microsoft Updates for Multiple Vulnerabilities

    Original release date: September 10, 2013 Systems Affected Windows Operating System and Components Microsoft Server Software Microsoft Office Internet Explorer Overview Select Microsoft software products contain multiple vulnerabilities. Microsoft has released updates to address these...
  19. TA13-168A: Microsoft Updates for Multiple Vulnerabilities

    Original release date: June 17, 2013 | Last revised: June 18, 2013 Systems Affected Microsoft Windows Microsoft Internet Explorer Microsoft Office Overview Select Microsoft software products contain multiple vulnerabilities. Microsoft has released updates to address these...
  20. MS13-012 - Critical : Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution

    Severity Rating: Critical Revision Note: V1.0 (February 12, 2013): Bulletin published. Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft Exchange Server. The most severe vulnerability is in Microsoft Exchange Server WebReady Document...