An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, aka ‘Windows Modules Installer Elevation of Privilege Vulnerability’.
NVD-CWE-noinfo
CVE-2020-13461
Username enumeration in present in Tufin SecureTrack. It’s affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor’s response: “This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames”.
CVE-2020-13466
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVE-2020-1347
An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka ‘Windows Storage Services Elevation of Privilege Vulnerability’.
CVE-2020-13471
Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVE-2020-1348
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka ‘Windows GDI Information Disclosure Vulnerability’.
