Security
Headlines
HeadlinesLatestCVEs

Tag

#Windows Local Security Authority Subsystem Service (LSASS)

CVE-2024-26209: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.

Microsoft Security Response Center
#vulnerability#microsoft#auth#Windows Local Security Authority Subsystem Service (LSASS)#Security Vulnerability
CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

**How could an attacker exploit this vulnerability?** An attacker could exploit the vulnerability by convincing, or waiting for, a user to connect to an Active Directory Domain Controller and then stealing network secrets. When the vulnerability is successfully exploited this could allow the attacker to retrieve sensitive data in plain-text which could be exploited for further attacks.

CVE-2023-36391: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

**What privileges could be gained by an attacker who successfully exploited this vulnerability?** An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.