| LPE via Insecure File Permissions (Service DLL Replacement) | Privileged Windows service | Code execution as SYSTEM | 2026 |
| Stack-Based Buffer Overflow in Privileged Logging Handler | Privileged Windows service | Code execution as SYSTEM | 2024 |
| Format String Vulnerability in Logging Component | Endpoint security product | Memory disclosure / corruption | 2024 |
| Integer Overflow in Kernel Entropy Routine | Windows kernel driver | Kernel denial of service | 2024 |
| Heap Buffer Overflow in Privileged Local RPC Service | Privileged RPC service | Code execution as SYSTEM | 2023 |
| LPE via Arbitrary Write and Self-Protection Bypass | Endpoint security product | Code execution as SYSTEM | 2023 |
| Arbitrary Write Primitive via Insecure Mount-Point Handling | Privileged Windows service | Arbitrary file write -> SYSTEM | 2023 |
| RPC Authorization Bypass Enables Unprivileged Service Access | Privileged RPC service | Privilege boundary bypass | 2023 |
| Self-Protection Bypass via Minifilter Logic Flaw | Windows minifilter driver | Security control bypass | 2023 |
| LPE via Unprivileged Database Modification | Endpoint security client | Code execution as SYSTEM | 2023 |
| Weak Database ACLs Allow Unprivileged Modification | Endpoint security client | Integrity / configuration bypass | 2023 |
| Out-of-Bounds Write via Insufficient IOCTL Validation | OEM kernel driver | Kernel memory corruption | 2022 |
| Out-of-Bounds Read/Write via Insufficient IOCTL Validation | OEM kernel driver | Kernel memory disclosure / corruption | 2022 |
| LPE via TOCTOU in Vendor Update Service | Privileged Windows service | Code execution as SYSTEM | 2022 |
| Integer Overflow in Privileged Optimization Service | Privileged Windows service | Memory corruption | 2022 |
| Arbitrary Delete Primitive via Insecure Mount-Point Handling | Privileged Windows service | Arbitrary file delete | 2022 |
| Unprotected Named Pipe Exposes Privileged Interface | Windows IPC / named pipe | Authorization bypass | 2021 |