Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.
| CVE | Module | CWE | Title Advisory text and compact technical context | Release | Exploited | Acknowledgement |
|---|---|---|---|---|---|---|
| CVE-2020-16863 |
Windows Remote Desktop Service
|
Windows Remote Desktop Service Denial of Service Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
VictorV (Tang Tianwen)
|
|
| CVE-2020-16927 |
Windows Remote Desktop Protocol (RDP)
|
Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
VictorV (Tang Tianwen)
|
|
| CVE-2020-16896 |
Windows Remote Desktop Protocol (RDP)
|
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
VictorV (Tang Tianwen)
|
|
| CVE-2020-16887 |
Windows Network Connections Service
|
Windows Network Connections Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16894 |
Windows NAT
|
Windows NAT Denial of Service Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Huichen Lin and Dong Seong Kim of School of Information Technology and Electrical Engineering - The University of Queensland
|
|
| CVE-2020-16889 |
Windows KernelStream
|
Windows KernelStream Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
nghiadt12(@nghiadt1098) from Viettel Cyber Security
|
|
| CVE-2020-16938 |
Windows Kernel
|
Windows Kernel Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Jonas Lykkegård
|
|
| CVE-2020-16901 |
Windows Kernel
|
Windows Kernel Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No | - | |
| CVE-2020-16890 |
Windows Kernel
|
Windows Kernel Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Nicolas Economou from Blue Frost Security
|
|
| CVE-2020-16902 |
Windows Installer
|
Windows Installer Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Abdelhamid Naceri (halov), an independent security researcher working for SSD Secure Disclosure
|
|
| CVE-2020-16892 |
Windows Image
|
Windows Image Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
anonymous
|
|
| CVE-2020-16891 |
Windows Hyper-V
|
Windows Hyper-V Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
HongZhenhao of IceSword Lab
|
|
| CVE-2020-1243 |
Windows Hyper-V
|
Windows Hyper-V Denial of Service Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Nicolas Economou from Blue Frost Security
|
|
| CVE-2020-1080 |
Windows Hyper-V
|
Windows Hyper-V Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Jonas Lykkegård
|
|
| CVE-2020-1047 |
Windows Hyper-V
|
Windows Hyper-V Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Saar Amar, Microsoft Security Response Center
|
|
| CVE-2020-16914 |
Windows GDI+
|
Windows GDI+ Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
|
|
| CVE-2020-16900 |
Windows Event System
|
Windows Event System Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Xuefeng Li (@lxf02942370) & Zhiniang Peng (@edwardzpeng
|
|
| CVE-2020-16895 |
Windows Error Reporting Manager
|
Windows Error Reporting Manager Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Tao Yan (@Ga1ois) from Palo Alto Networks
|
|
| CVE-2020-16909 |
Windows Error Reporting
|
Windows Error Reporting Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No | - | |
| CVE-2020-16905 |
Windows Error Reporting
|
Windows Error Reporting Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16919 |
Windows Enterprise App Management Service
|
Windows Enterprise App Management Service Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
JeongOh Kyea (kkokkokye) of THEORI
|
|
| CVE-2020-16968 |
Windows Camera Codec Pack
|
Windows Camera Codec Pack Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
|
|
| CVE-2020-16967 |
Windows Camera Codec Pack
|
Windows Camera Codec Pack Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Hossein Lotfi of Trend Micro's Zero Day Initiative
|
|
| CVE-2020-16935 |
Windows COM Server
|
Windows COM Server Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Anonymous researcher
|
|
| CVE-2020-16916 |
Windows COM Server
|
Windows COM Server Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Anonymous researcher
|
|
| CVE-2020-16976 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16975 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16974 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16973 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16972 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16936 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16912 |
Windows Backup Service
|
Windows Backup Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Yuki Chen
|
|
| CVE-2020-16920 |
Windows Application Compatibility Client Library
|
Windows Application Compatibility Client Library Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Feeker Wang from Codesafe Team of Legendsec at Qi'anxin Group
|
|
| CVE-2020-16876 |
Windows Application Compatibility Client Library
|
Windows Application Compatibility Client Library Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Tao Yan (@Ga1ois), Ken Hsu, and Qi Deng from Palo Alto Networks
Yuki Chen |
|
| CVE-2020-16940 |
Windows - User Profile Service
|
Windows - User Profile Service Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Abdelhamid Naceri working with Trend Micro's Zero Day Initiative
|
|
| CVE-2020-16877 |
Windows
|
Windows Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Donato Ferrante of IOActive
|
|
| CVE-2020-16913 |
Win32k
|
Win32k Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Alex Ionescu, CrowdStrike Inc.
|
|
| CVE-2020-16907 |
Win32k
|
Win32k Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Jarvis_1oop of Pinduoduo Security Research Lab
|
|
| CVE-2020-16995 |
Network Watcher Agent Virtual Machine Extension for Linux
|
Network Watcher Agent Virtual Machine Extension for Linux Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Paul Litvak
|
|
| CVE-2020-16897 |
NetBT
|
NetBT Information Disclosure Vulnerability
No CVSS vector published
|
2020-10-13 | No | ||
| CVE-2020-16923 |
Microsoft Graphics Components
|
Microsoft Graphics Components Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Zhangjie and willJ
|
|
| CVE-2020-1167 |
Microsoft Graphics Components
|
Microsoft Graphics Components Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
rgod working with Trend Micro's Zero Day Initiative
|
|
| CVE-2020-16924 |
Jet Database Engine
|
Jet Database Engine Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Zhibin Zhang of Palo Alto Networks
|
|
| CVE-2020-16939 |
Group Policy
|
Group Policy Elevation of Privilege Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Jarvis_1oop of Pinduoduo Security Research Lab
Nabeel Ahmed of NTT working with Trend Micro's Zero Day Initiative |
|
| CVE-2020-16911 |
GDI+
|
GDI+ Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
0xfff
|
|
| CVE-2020-17003 |
Base3D
|
Base3D Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
rgod working with Trend Micro's Zero Day Initiative
|
|
| CVE-2020-16918 |
Base3D
|
Base3D Remote Code Execution Vulnerability
No CVSS vector published
|
2020-10-13 | No |
Reported By
Keqi Hu
|
| CVE | Module | CWE | Title Advisory text and compact technical context | Release | Exploited | Acknowledgement |
|---|---|---|---|---|---|---|
| CVE-2010-0298 |
The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code which allows guest OS users to cause a
|
The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region a related issue to CVE-2010-0306.
No CVSS vector published
|
2020-09-25 | - | - | |
| CVE-2010-0309 |
The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure which allows guest OS users to cause a
|
The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.
No CVSS vector published
|
2020-09-25 | - | - | |
| CVE-2013-0223 |
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a
|
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command when using the -i switch which triggers a stack-based buffer overflow in the alloca function.
No CVSS vector published
|
2020-09-25 | - | - |