Skip to content
Threat Feed

CPE

Cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*

10 briefs RSS
high advisory

Microsoft Dataverse Privilege Escalation Vulnerability

A vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.

Dataverse privilege-escalation cloud-security vulnerability high-confidence-source
1t 1c
low advisory

Denial of Service Vulnerability in libarchive

A memory corruption vulnerability in libarchive (CVE-2024-20696) allows a local attacker to cause a Denial of Service condition through the processing of specially crafted archive files.

libarchive
1t 1c
high advisory

Multiple Privilege Escalation Vulnerabilities in Microsoft Authenticator and Xbox Gaming Services

Local attackers can exploit multiple vulnerabilities in Microsoft Authenticator and Xbox Gaming Services to achieve elevated privileges on Windows systems.

Microsoft Authenticator +1 privilege-escalation windows vulnerability
1t 2c
medium advisory

Privilege Escalation Vulnerability in Microsoft Windows Package Manager

A local privilege escalation vulnerability in the Microsoft Windows Package Manager allows an authenticated local attacker to gain elevated privileges on the host system.

Windows Package Manager privilege-escalation windows vulnerability
1c
critical threat

August 2026 Microsoft Security Update Analysis

Microsoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 5c updated
medium advisory

Suspicious Child Processes of consent.exe

Detection of unauthorized child process creation by the Windows UAC consent.exe binary, a common indicator of UAC bypass and privilege escalation activity.

Windows privilege-escalation uac-bypass
1r 3t 1c
high advisory

Suspicious Microsoft Office Child Process Activity

Microsoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.

Microsoft Office
1r 3t 1c
high threat

Microsoft Security Updates — August 2026

Roundup of Microsoft security advisories published in August 2026.

roundup
29c updated
high advisory

Suspicious Rundll32 Execution Without Command-Line Arguments

The execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.

PoC Windows Print Spooler defense-evasion windows rundll32
2r 1t 1c updated
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated