CVE-2022-30170 Windows Credential Roaming Service Elevation of Privilege Vulnerability

Posted on Tuesday March 11, 2025

In the Security Updates table added Windows Server 2022, 23H2 Edition (Server Core installation) as it is affected by this vulnerability. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.

 

CVE-2024-30098 Windows Cryptographic Services Security Feature Bypass Vulnerability

Posted on Tuesday March 11, 2025

The following updates have been made to CVE-2024-30098: 1. In the Security Updates table, added all supported versions of the following as they are affected by this vulnerability: Windows 11 24H2 and Windows Server 2025. 2. To comprehensively address this vulnerability, Microsoft has released March 2025 security updates for all affected versions of Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2022 23H2 Edition, Windows 10, and Windows 11. 3. Updated the "Are there any further actions I need to take to be protected from this vulnerability?" FAQ to state that Starting with the April 2025, the fix will automatically generate an audit event in cases where the Cryptographic Service Provider (CSP) is being used with RSA keys. If you have not already enabled the fix using the DisableCapiOverrideForRSA setting, you should monitor your systems for any error events in the Windows system event log. See the FAQ section of this CVE for more information.

 

CVE-2025-26634 Windows Core Messaging Elevation of Privileges Vulnerability

Posted on Tuesday March 11, 2025

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.

 

CVE-2025-26645 Remote Desktop Client Remote Code Execution Vulnerability

Posted on Tuesday March 11, 2025

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

 

CVE-2025-26633 Microsoft Management Console Security Feature Bypass Vulnerability

Posted on Tuesday March 11, 2025

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

 

CVE-2025-26631 Visual Studio Code Elevation of Privilege Vulnerability

Posted on Tuesday March 11, 2025

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

 

Page:   123456...119

Celebrating 35+ Years

Off-Site Cloud Backups

Contact Us

Support Ends for Windows 10 22H2, Windows Server 2012 R2, Exchange 2013, Office 2016