Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-21417: Windows Text Services Framework Elevation of Privilege Vulnerability

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker could use this vulnerability to elevate privileges from a Low Integrity Level in a contained (“sandboxed”) execution environment to a Medium Integrity Level or a High Integrity Level.

Please refer to AppContainer isolation and Mandatory Integrity Control for more information.

Microsoft Security Response Center
#vulnerability#windows#Windows CoreMessaging#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-49060: Azure Stack HCI Elevation of Privilege Vulnerability