| CVE | Vendors | Products | Updated | CVSS v3.1 | 
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 
    
    
    
        | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | 
    
    
    
        | Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 
    
    
    
        | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 
    
    
    
        | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | 
    
    
    
        | Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 
    
    
    
        | Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. | 
    
    
    
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. | 
    
    
    
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. | 
    
    
    
        | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. |