Tag
#vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
**According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?** Successful exploitation of this vulnerability requires an attacker to win a race condition.
**What kind of security feature could be bypassed by successfully exploiting this vulnerability?** An attacker who successfully exploited this vulnerability could bypass Visual Studio Code sensitive file protections.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
No cwe for this issue in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.