Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
CVSS
6.5
Update availability
Security update available
Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +28 more
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVSS
6.5
Update availability
Security update available
Affected: Skype for Business Server 2015 CU13 · Skype for Business Server 2019 CU8 · +1 more
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVSS
6.5
Update availability
Security update available
Affected: Skype for Business Server 2015 CU13 · Skype for Business Server 2019 CU8 · +1 more
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS
8.8
Update availability
Security update available
Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS
8.8
Update availability
Security update available
Affected: Microsoft SQL Server 2017 for x64-based Systems (CU 31) · Microsoft SQL Server 2017 for x64-based Systems (GDR) · +6 more
The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.
Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.
Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.