Windows · Fixed build
10.0.22631.7376
MSRC advisory17 CVEs fixed by this build, deployed across 1 Windows SKUs.
- Published on
- 2026-07-14
- SKUs covered
- 1
- CVEs fixed
- 17
Windows SKUs covered by this build
The SKUs below share this MSRC build number. Deploying the corresponding KB secures all of them at once.
- CISA KEV
- 1
- Critical
- 2
- High
- 11
- NVD pending
- 0
CVEs fixed by this build
| CVE | Severity | KEV | Published | Description |
|---|---|---|---|---|
|
CVE-2026-32202
KEV
Windows Shell Spoofing Vulnerability |
HIGH 4.3 | KEV | Windows Shell Spoofing Vulnerability | |
|
CVE-2026-49172
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-42990
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-50471
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-58601
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileg… |
HIGH 7.8 | — | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-42982
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate … |
HIGH 7.8 | — | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-44800
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.8 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-40378
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an una… |
HIGH 7.5 | — | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over … | |
|
CVE-2026-58640
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
HIGH 7.3 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | |
|
CVE-2026-58629
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56173
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-48572
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer al… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p… | |
|
CVE-2026-48571
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-34348
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information ove… |
MEDIUM 6.5 | — | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | |
|
CVE-2026-34346
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized a… |
MEDIUM 5.5 | — | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | |
|
CVE-2026-33842
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
|
CVE-2026-34328
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to di… |
MEDIUM 5.5 | — | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |