Posted on Tuesday April 15, 2025
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
Posted on Tuesday April 15, 2025
To comprehensively address CVE-2024-21302, Microsoft has released April 2025 security updates for all supported editions of Windows. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.
Posted on Tuesday April 08, 2025
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Posted on Tuesday April 08, 2025
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Posted on Tuesday April 08, 2025
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Posted on Tuesday April 08, 2025
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.