References https://www.cnvd.org.cn/flaw/show/CNVD-2024-20288 https://avd.aliyun.com/detail?id=AVD-2020-1110 https://www.anquanke.com/post/id/298973 https://cve.imfht.com/detail/CVE-2024-21432 https://zone.ci/aliyun/ali_nvd/365188.html https://nvd.nist.gov/vuln/detail/cve-2025-21204 https://cyberdom.blog/abusing-the-windows-update-stack-to-gain-system-access-cve-2025-21204/ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38163 https://www.rapid7.com/db/vulnerabilities/microsoft-windows-cve-2024-38202/ https://rewterz.com/threat-advisory/critical-windows-update-stack-flaw-enables-code-execution-and-privilege-escalation
Related Vulnerabilities大华-智慧园区综合管理平台 updateAccessChannelByVisit SQL注入漏洞PoCCVE-2025-13342: DynamiApps Frontend Admin <= 3.28.20 - Unauthenticated Arbitrary Options Update金和OA /c6/JHSoft.Web.CostControl/BudgetExecution/VouchUpdate.aspx SQL 注入漏洞时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞PoCCVE-2025-12841: WordPress Bookit < 2.5.1 - Unauthenticated Stripe Settings UpdateWordPress WebStack主题 /wp-admin/admin-ajax.php 文件上传漏洞(CVE-2026-1555)CentreStack 本地文件包含漏洞(CVE-2025-11371)NocoBase /api/sqlCollection:update SQL 注入漏洞(CVE-2026-41641)Apache CloudStack /client/api/ 默认口令漏洞Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)宏景 ehr /services/HrpService updateHolidays XML 外部实体注入漏洞Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)PoC深信服运维安全管理系统 /fort/csspost;help/update 命令执行漏洞