Medium · CVSS 6.5
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
Published Oct 1, 2024 · Updated Aug 25, 2026
Medium · CVSS 6.5
Power BI Report Server Spoofing Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.9
Power BI Report Server Spoofing Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.1
Remote Desktop Protocol Server Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7
Windows Kernel Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Windows Kernel Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 5.5
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 4.3
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published Oct 18, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.6
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Oct 17, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.5
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Oct 17, 2024 · Updated Aug 19, 2026
High · CVSS 7.6
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Oct 17, 2024 · Updated Aug 19, 2026
Medium · CVSS 5.9
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Oct 17, 2024 · Updated Aug 19, 2026
High · CVSS 8.6
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
Published Oct 15, 2024 · Updated Aug 19, 2026
High · CVSS 7.5
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
Published Oct 15, 2024 · Updated Aug 19, 2026
High · CVSS 7.4
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
Published Oct 9, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Winlogon Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 5.5
Visual Studio Collector Service Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Remote Desktop Client Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.7
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 5.5
Code Integrity Guard Security Feature Bypass Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.7
Windows Scripting Engine Security Feature Bypass Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.5
Windows Hyper-V Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.3
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Microsoft Management Console Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 5.6
Sudo for Windows Spoofing Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.4
Windows Kernel Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.5
Windows Hyper-V Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.5
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.5
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.5
Windows Mobile Broadband Driver Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.5
Windows Mobile Broadband Driver Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.5
Windows Mobile Broadband Driver Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.5
Windows Mobile Broadband Driver Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Windows Graphics Component Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.5
Windows Mobile Broadband Driver Denial of Service Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.4
NT OS Kernel Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.3
Windows Shell Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 7.8
Windows Storage Elevation of Privilege Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026