CVE-2023-35342: Windows Image Acquisition Elevation of Privilege Vulnerability
Windows Image Acquisition Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Browse CVE records published in July 2023, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 2183 matching CVEs · Page 15 of 44.
Windows Image Acquisition Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows CryptoAPI Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Peer Name Resolution Protocol Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Win32k Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows MSHTML Platform Security Feature Bypass Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
MediaWiki PandocUpload Extension Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Remote Desktop Protocol Security Feature Bypass
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Local Security Authority (LSA) Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Extended Negotiation Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Authentication Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Transaction Manager Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows CDP User Components Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Print Spooler Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows OLE Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Deployment Services Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Deployment Services Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Raw Image Extension Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Installer Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Paint 3D Remote Code Execution Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Remote Desktop Security Feature Bypass Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
OLE Automation Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Update Orchestrator Service Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Cryptographic Information Disclosure Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Remote Procedure Call Runtime Denial of Service Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Windows Win32k Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
.NET and Visual Studio Elevation of Privilege Vulnerability
Published Jul 11, 2023 · Updated Jan 1, 2025
Dynamics 365 Finance Spoofing Vulnerability
Published Jul 14, 2023 · Updated Jan 1, 2025
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.
Published Jul 17, 2023 · Updated Dec 12, 2024
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.
Published Jul 17, 2023 · Updated Dec 12, 2024
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The SCEP server configuration URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
Published Jul 11, 2023 · Updated Dec 10, 2024
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow an attacker to gain root access by running a crafted binary leveraging an exported function from a shared library. The attacker must have shell access to the device in order to exploit this vulnerability.
Published Jul 5, 2023 · Updated Dec 5, 2024
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Published Jul 4, 2023 · Updated Dec 5, 2024
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07549928.
Published Jul 4, 2023 · Updated Dec 4, 2024