KB4457951: Windows guidance to protect against speculative execution ...
Microsoft is aware of new variants of the class of attack known as speculative execution side-channel vulnerabilities. The variants are named L1 Terminal Fault (L1TF) and Microarchitectural Data Sampling (MDS). An attacker who can successfully exploit L1TF or MDS may be able to read privileged data across trust boundaries.
Microsoft Security Advisory: Insecure library loading could allow ...
The MANIFEST files (.manifest) and the MUM files (.mum) that are installed for each environment are listed separately. MUM and MANIFEST files, and the associated security catalog (.cat) files, are critical to maintaining the state of the updated component.
Customer guidance for CVE-2019-0708 | Remote Desktop Services Remote ...
Microsoft is aware that some customers are running versions of Windows that no longer receive mainstream support. That means those customers will not have received any security updates to protect their systems from CVE-2019-0708, which is a critical remote code execution vulnerability.
MS10-081: Vulnerability in the Windows common control library could ...
Resolves a vulnerability in Windows Explorer that could allow remote code execution if a user visited a specially crafted webpage.
MS13-098: Vulnerability in Windows could allow remote code execution ...
Resolves a vulnerability in Windows that could allow remote code execution if user or application runs or installs a specially crafted, signed portable executable (PE) file on an affected system.
MS11-038: Vulnerability in OLE Automation could allow remote code ...
Resolves a vulnerability in Microsoft Windows Object Linking and Embedding (OLE) Automation that could allow remote code execution if a user visits a website that contains a specially crafted Windows Metafile (WMF) image.
KB5017718 - FIX: Access violation when you use the query_post_execution ...
Assume that you use the query_post_execution_plan_profile extended event (XEvent) in Microsoft SQL Server 2019. If the engine's cache is filled during XEvent generation, and you reuse the same execution plan, this cache points to invalid memory and causes an access violation. Resolution
MS08-038: Vulnerability in Windows Explorer could allow remote code ...
Resolves a vulnerability in Windows Explorer that could allow remote code execution when a specially crafted saved-search file is opened and saved.
KB954593 - MS08-052: Vulnerabilities in GDI+ could allow remote code ...
Resolves several vulnerabilities in Microsoft Windows GDI+ that could allow remote code execution if a user viewed a specially crafted image file using affected software.
MS15-100: Vulnerability in Windows Media Center could allow remote code ...
The vulnerability could allow remote code execution if Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. An attacker who successfully exploits this vulnerability could gain the same user rights as the current user.