Microsoft Windows Local Security Authority Subsystem Service是美国微软(Microsoft)公司的一个内部程序,负责运行Windows系统安全政策。它在用户登录时电脑单机或服务器时,验证用户身份,管理用户密码变更,并产生访问字符。它也会在窗口安全日志中留下应有的记录。 Microsoft Windows Local Security Authority Subsystem Service (LSASS)存在安全漏洞。攻击者利用该漏洞可以提升权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 11 version 22H3 | 10.0.22631.0 ~ 10.0.22621.2861 | - |
|
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 ~ 10.0.22631.2861 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-36019 | 9.6 CRITICAL | Microsoft Power Platform Connector Spoofing Vulnerability |
| CVE-2023-35630 | 8.8 HIGH | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
| CVE-2023-35641 | 8.8 HIGH | Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
| CVE-2023-36006 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-35639 | 8.8 HIGH | Microsoft ODBC Driver Remote Code Execution Vulnerability |
| CVE-2023-35628 | 8.1 HIGH | Windows MSHTML Platform Remote Code Execution Vulnerability |
| CVE-2023-35634 | 8.0 HIGH | Windows Bluetooth Driver Remote Code Execution Vulnerability |
| CVE-2023-35631 | 7.8 HIGH | Win32k Elevation of Privilege Vulnerability |
| CVE-2023-36696 | 7.8 HIGH | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2023-36011 | 7.8 HIGH | Win32k Elevation of Privilege Vulnerability |
| CVE-2023-21740 | 7.8 HIGH | Windows Media Remote Code Execution Vulnerability |
| CVE-2023-35632 | 7.8 HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2023-35644 | 7.8 HIGH | Windows Sysmain Service Elevation of Privilege Vulnerability |
| CVE-2023-35633 | 7.8 HIGH | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2023-36020 | 7.6 HIGH | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2023-35638 | 7.5 HIGH | DHCP Server Service Denial of Service Vulnerability |
| CVE-2023-36005 | 7.5 HIGH | Windows Telephony Server Elevation of Privilege Vulnerability |
| CVE-2023-35643 | 7.5 HIGH | DHCP Server Service Information Disclosure Vulnerability |
| CVE-2023-36004 | 7.5 HIGH | Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability |
| CVE-2023-35621 | 7.5 HIGH | Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet