CWE-822 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-822 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2024-21338Windows Kernel Elevation of Privilege Vulnerability59.8%높음7.8● 실제 악용이 확인됨CVE-2024-35250Windows Kernel-Mode Driver Elevation of Privilege Vulnerability25.2%높음7.8● 실제 악용이 확인됨CVE-2023-29360Microsoft Streaming Service Elevation of Privilege Vulnerability21.6%높음8.4● 실제 악용이 확인됨CVE-2023-36033Windows DWM Core Library Elevation of Privilege Vulnerability10.9%높음7.8● 실제 악용이 확인됨CVE-2025-24990Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with…6.4%높음7.8CVE-2026-72938Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows …0.9%보통6.5CVE-2026-72956Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disc…0.9%보통6.5CVE-2026-69569Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to d…0.9%보통5.7
전체 목록
32건
CVE-2026-69717Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over…0.7%높음8.0
CVE-2026-103764Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader …0.6%심각9.3
CVE-2026-78444Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over…0.5%높음8.1
CVE-2026-67378Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.0.5%높음8.5
CVE-2026-78451Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to e…0.4%보통6.8
CVE-2026-69874Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.0.3%높음8.2
CVE-2026-69475Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate priv…0.3%높음7.8
CVE-2026-69900Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to el…0.3%높음7.8
CVE-2026-83498Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized atta…0.3%높음7.8
CVE-2026-83939Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privilege…0.3%높음8.2
CVE-2026-69501Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privilege…0.2%높음7.0
CVE-2026-80083Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.0.2%높음8.8
CVE-2026-94403A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the…0.2%높음8.5
CVE-2025-59607Memory Corruption when copying large input data exceeds normal allocation limits.0.1%높음7.8
CVE-2026-97876A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Sec…0.1%보통6.4
CVE-2026-58007Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperl…0.1%높음8.3
CVE-2026-58006Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperl…0.1%높음8.3
CVE-2026-102757An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its…0.1%높음8.5
CVE-2026-102709Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functi…0.1%높음8.4
CVE-2026-33964An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer deref…0.1%보통6.4
CVE-2026-90890ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vuln…0.1%보통6.8
CVE-2026-102710Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing …0.1%심각9.3
CVE-2026-91795Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially…0.1%높음7.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.