| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
| The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below. |
| Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. |
| Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
| Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
| SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
makes brute-forcing the key easier. See V6 in BLERP paper linked below. |
| is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed. |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
| Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below. |
| Use after free in Winlogon allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
| Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. |
| Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
| Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below. |
| Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
| Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below |
| Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |