Headline
CVE-2023-36401: Microsoft Remote Registry Service Remote Code Execution Vulnerability
According to the CVSS metric, privileges required is low (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires the attacker must be an authenticated user on the network who is a member of the performance log users group.
Although this group defaults to only Administrators, it is possible for an Administrator to add other standard users to this group.
Microsoft Security Response Center: Latest News
CVE-2025-48822: Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability