See how microsoft compares to other vendors in security performance
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to ERRraisedata().
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Azure Arc Elevation of Privilege Vulnerability
Azure Logic Apps Elevation of Privilege Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Microsoft Fabric Elevation of Privilege Vulnerability
Azure Arc Elevation of Privilege Vulnerability
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Azure Confidential Ledger Remote Code Execution Vulnerability
Microsoft Teams Elevation of Privilege Vulnerability
Azure SQL Database Elevation of Privilege Vulnerability
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Copilot Cowork Elevation of Privilege Vulnerability
Azure Logic Apps Information Disclosure Vulnerability
Azure SRE Agent Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Azure Storage Explorer Elevation of Privilege Vulnerability
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Summary Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Details
New network path creations and removals triggered by incoming packets can lead to a pointer invalidation.
Patches
- Guard path promotion e0f55b5
Impact
An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Azure AI Language Elevation of Privilege Vulnerability
Copilot Studio Elevation of Privilege Vulnerability