CWE-822
13 CVEs of this weakness class.
- CVE-2024-21338HIGH 7.8KEVEPSS 52%
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2026-40369HIGH 7.8Real · low riskEPSS 5%
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-50424HIGH 7.5Real · low riskEPSS 1%
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
- CVE-2026-48137CRIT 9.1Real · low riskEPSS 0%
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions.
- CVE-2026-58596HIGH 8.3Real · low riskEPSS 0%
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-48580MED 5.5EPSS 0%
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-45645HIGH 7.8Real · low riskEPSS 0%
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55138MED 5.5EPSS 0%
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-50479HIGH 7.8Real · low riskEPSS 0%
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-55136HIGH 7.8Real · low riskEPSS 0%
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-50382HIGH 8.8Real · low riskEPSS 0%
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
- CVE-2026-50441HIGH 7.8Real · low riskEPSS 0%
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-48340HIGH 7.8Real · low riskEPSS 0%
Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.