An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center exposes functionality that allows low-privileged users to interact with the device and exploit a stack buffer overflow via specially crafted IOCTL requests and elevate system privileges.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
This module uses ioctls Write to IO Ports and generate a reboot
This module exploits a JSON deserialization vulnerability present in the test alert actions of SolarWinds Orion Network Performance Monitor. The deployed agent will run with the privileges of the "IIS Worker Process" process (NT AUTHORITY\NETWORK SERVICE).
A vulnerability in Pulse Connect Secure could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface. The deployed agent will run with ROOT privileges.
The vulnerability has been dubbed PrintNightmare and is tracked as CVE-2021-34527. The flaw is due to the Windows Print Spooler service improperly performing privileged file operations. Microsoft says the flaw can be exploited by an authenticated user calling RpcAddPrinterDriverEx(). When exploited, an attacker gains SYSTEM privileges and can execute arbitrary code, install programs, view, change, or delete data or create new accounts with full user rights.
A Local Privilege Escalation vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges.
An elevation of privilege vulnerability exists in the way the Windows Graphics Component handles objects in memory.
This module crashes the target machine producing a blue screen by sending a malformed HTTP packet.
Pagination
- Previous page
- Page 32
- Next page