CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. |
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. |
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. |
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. |
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. |
Microsoft Defender for Endpoint on Android Spoofing Vulnerability |
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. |
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability |
Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
1Microsoft 1Defender For Endpoint Nov 21, 2024 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Microsoft Defender for Endpoint Tampering Vulnerability |
1Microsoft 2Defender For Endpoint Defender For Endpoint Edr SensorNov 21, 2024 Mar 9, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Defender for Endpoint Spoofing Vulnerability |