Tag
#auth
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
No cwe for this issue in Windows Hyper-V allows an authorized attacker to disclose information over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Visual Studio allows an authorized attacker to execute code locally.
**How could an attacker exploit this vulnerability?** An authenticated attacker with explicit permissions could exploit the vulnerability by logging in to the SQL server and could then elevate their privileges to sysadmin.
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges locally.