Windows
Windows Windows 11 26H1 · 2026-H1
Advisory officielWindows Windows 11 26H1 · 2026-H1 corrige 1574 CVE, dont 9 activement exploitées (CISA KEV). Les versions antérieures restent exposées à ces vulnérabilités.
- Date de sortie
- —
- Fin de support
- —
- CVE corrigées
- 1574
- KEV CISA
- 9
53 critique · 1244 élevé
CVE corrigées
| CVE |
|---|
|
CVE-2026-33824
CRITICAL 9.8
KEV
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-21510
HIGH 8.8
KEV
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21513
HIGH 8.8
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-81963
HIGH 7.8
KEV
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2026-21519
HIGH 7.8
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21533
HIGH 7.8
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-68820
HIGH 7.0
KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-32202
Exploit
MEDIUM 4.3
KEV
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-57092
CRITICAL 9.9
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-77493
CRITICAL 9.8
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73009
CRITICAL 9.8
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72983
CRITICAL 9.8
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72982
CRITICAL 9.8
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70296
CRITICAL 9.8
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69910
CRITICAL 9.8
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69824
CRITICAL 9.8
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69829
CRITICAL 9.8
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69768
CRITICAL 9.8
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69715
CRITICAL 9.8
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69590
CRITICAL 9.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-69586
CRITICAL 9.8
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69579
CRITICAL 9.8
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69525
CRITICAL 9.8
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69496
CRITICAL 9.8
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69491
CRITICAL 9.8
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69463
CRITICAL 9.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69431
CRITICAL 9.8
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-68839
CRITICAL 9.8
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69276
HIGH 9.8
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability |
|
CVE-2026-69408
HIGH 9.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-69493
HIGH 9.8
Windows Event Logging Service Remote Code Execution Vulnerability |
|
CVE-2026-69769
CRITICAL 9.8
Windows HTTP Print Provider Remote Code Execution Vulnerability |
|
CVE-2026-69819
HIGH 9.8
RPC Runtime Library Remote Code Execution Vulnerability |
|
CVE-2026-62815
CRITICAL 9.8
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56190
CRITICAL 9.8
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56188
CRITICAL 9.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to… |
|
CVE-2026-50447
CRITICAL 9.8
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-54990
CRITICAL 9.8
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-49172
CRITICAL 9.8
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42990
CRITICAL 9.8
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-47291
CRITICAL 9.8
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-45657
CRITICAL 9.8
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-44815
CRITICAL 9.8
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-41096
CRITICAL 9.8
Windows DNS Client Remote Code Execution Vulnerability |
|
CVE-2026-50380
CRITICAL 9.6
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42904
CRITICAL 9.6
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. |
|
CVE-2026-49798
CRITICAL 9.3
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-45602
CRITICAL 9.1
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. |
|
CVE-2025-10263
CRITICAL 9.1
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C… |
|
CVE-2026-83992
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-81955
HIGH 8.8
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-80096
HIGH 8.8
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-80083
HIGH 8.8
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally. |
|
CVE-2026-77495
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73023
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73012
HIGH 8.8
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-73013
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73016
HIGH 8.8
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73006
HIGH 8.8
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72986
HIGH 8.8
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72959
HIGH 8.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-72960
HIGH 8.8
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72950
HIGH 8.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-72940
HIGH 8.8
Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-71352
HIGH 8.8
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network. |
|
CVE-2026-70586
HIGH 8.8
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70203
HIGH 8.8
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69860
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69729
HIGH 8.8
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network. |
|
CVE-2026-69676
HIGH 8.8
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network. |
|
CVE-2026-69669
HIGH 8.8
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69628
HIGH 8.8
Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network. |
|
CVE-2026-69598
HIGH 8.8
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69601
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69518
HIGH 8.8
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69499
HIGH 8.8
Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69461
HIGH 8.8
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69291
HIGH 8.8
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62706
HIGH 8.8
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62744
HIGH 8.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-68828
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69334
HIGH 8.8
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability |
|
CVE-2026-69360
HIGH 8.8
Microsoft Office Word Remote Code Execution Vulnerability |
|
CVE-2026-69386
HIGH 8.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-69434
HIGH 8.8
Windows URL Moniker Remote Code Execution Vulnerability |
|
CVE-2026-69485
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69494
HIGH 8.8
Windows Event Logging Service Remote Code Execution Vulnerability |
|
CVE-2026-69495
HIGH 8.8
Windows Event Logging Service Remote Code Execution Vulnerability |
|
CVE-2026-69511
HIGH 8.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-69740
CRITICAL 8.8
Windows Hello Elevation of Privilege Vulnerability |
|
CVE-2026-69772
HIGH 8.8
Windows Network File System Remote Code Execution Vulnerability |
|
CVE-2026-69784
CRITICAL 8.8
Windows Hello Elevation of Privilege Vulnerability |
|
CVE-2026-72933
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability |
|
CVE-2026-73018
CRITICAL 8.8
Graphic Fonts Remote Code Execution Vulnerability |
|
CVE-2026-77504
CRITICAL 8.8
Microsoft Office Word Remote Code Execution Vulnerability |
|
CVE-2026-83996
HIGH 8.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-83998
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-62822
HIGH 8.8
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62816
HIGH 8.8
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. |
|
CVE-2026-62817
HIGH 8.8
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. |
|
CVE-2026-62800
HIGH 8.8
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. |
|
CVE-2026-62795
HIGH 8.8
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62785
HIGH 8.8
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62790
HIGH 8.8
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. |
|
CVE-2026-62784
HIGH 8.8
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. |
|
CVE-2026-49179
HIGH 8.8
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code… |
|
CVE-2026-58626
HIGH 8.8
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-58594
HIGH 8.8
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-58534
HIGH 8.8
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57094
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57090
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57087
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56647
HIGH 8.8
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56194
HIGH 8.8
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50692
HIGH 8.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50687
HIGH 8.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50670
HIGH 8.8
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50666
HIGH 8.8
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50489
HIGH 8.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50474
HIGH 8.8
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50477
HIGH 8.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50413
HIGH 8.8
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50398
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50385
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50382
HIGH 8.8
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. |
|
CVE-2026-50369
HIGH 8.8
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50360
HIGH 8.8
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-58608
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker t… |
|
CVE-2026-54999
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… |
|
CVE-2026-54982
HIGH 8.8
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. |
|
CVE-2026-54107
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… |
|
CVE-2026-50342
HIGH 8.8
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49795
HIGH 8.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49178
HIGH 8.8
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-47653
HIGH 8.8
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-47289
HIGH 8.8
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42985
HIGH 8.8
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-34329
HIGH 8.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2026-40403
CRITICAL 8.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2026-32225
HIGH 8.8
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-26167
HIGH 8.8
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-32157
CRITICAL 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-23669
HIGH 8.8
RPC Runtime Library Remote Code Execution Vulnerability |
|
CVE-2026-24283
HIGH 8.8
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability |
|
CVE-2026-25177
HIGH 8.8
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-25188
HIGH 8.8
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-21255
HIGH 8.8
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2026-50340
HIGH 8.5
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69638
HIGH 8.4
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-69479
HIGH 8.4
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-77503
HIGH 8.4
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-54128
HIGH 8.4
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54992
HIGH 8.4
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54122
HIGH 8.4
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49184
HIGH 8.4
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-45641
HIGH 8.4
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
|
CVE-2026-45607
HIGH 8.4
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. |
|
CVE-2026-44810
HIGH 8.4
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-32221
HIGH 8.4
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32091
HIGH 8.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-32162
HIGH 8.4
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2026-56179
HIGH 8.3
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-56181
HIGH 8.3
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-85921
HIGH 8.2
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83939
HIGH 8.2
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-81354
HIGH 8.2
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72962
HIGH 8.2
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72958
HIGH 8.2
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72961
HIGH 8.2
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69906
HIGH 8.2
Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69874
HIGH 8.2
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69846
HIGH 8.2
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69820
HIGH 8.2
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50680
HIGH 8.2
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50429
HIGH 8.2
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-47652
HIGH 8.2
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. |
|
CVE-2026-83997
HIGH 8.1
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78449
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72981
HIGH 8.1
Use after free in IP Helper allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72936
HIGH 8.1
Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70563
HIGH 8.1
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-70342
HIGH 8.1
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-69438
HIGH 8.1
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69325
HIGH 8.1
Microsoft JScript Remote Code Execution Vulnerability |
|
CVE-2026-69524
HIGH 8.1
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
|
CVE-2026-69546
HIGH 8.1
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
|
CVE-2026-69732
HIGH 8.1
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability |
|
CVE-2026-69786
HIGH 8.1
Windows Text Shaping Remote Code Execution Vulnerability |
|
CVE-2026-66802
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized a… |
|
CVE-2026-62889
HIGH 8.1
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62819
HIGH 8.1
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-62792
HIGH 8.1
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62781
HIGH 8.1
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56186
HIGH 8.1
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. |
|
CVE-2026-50686
HIGH 8.1
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50487
HIGH 8.1
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-50460
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… |
|
CVE-2026-50439
HIGH 8.1
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-54995
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50694
HIGH 8.1
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-49164
HIGH 8.1
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42900
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri… |
|
CVE-2026-45635
HIGH 8.1
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a netw… |
|
CVE-2026-45599
HIGH 8.1
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42981
HIGH 8.1
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42974
HIGH 8.1
Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-40415
HIGH 8.1
Windows TCP/IP Remote Code Execution Vulnerability |
|
CVE-2026-33827
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… |
|
CVE-2024-49123
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2024-49132
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2024-43582
CRITICAL 8.1
Remote Desktop Protocol Server Remote Code Execution Vulnerability |
|
CVE-2026-69875
HIGH 8.0
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69847
HIGH 8.0
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. |
|
CVE-2026-69826
HIGH 8.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69777
HIGH 8.0
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges over an adjacent network. |
|
CVE-2026-69773
HIGH 8.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69727
HIGH 8.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69717
HIGH 8.0
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69689
HIGH 8.0
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69681
HIGH 8.0
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69643
HIGH 8.0
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69623
HIGH 8.0
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network. |
|
CVE-2026-69625
HIGH 8.0
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69619
HIGH 8.0
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69503
HIGH 8.0
Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69505
HIGH 8.0
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69481
HIGH 8.0
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69423
HIGH 8.0
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69371
HIGH 8.0
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69332
HIGH 8.0
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69322
HIGH 8.0
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68838
HIGH 8.0
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68834
HIGH 8.0
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68827
HIGH 8.0
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68876
HIGH 8.0
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
|
CVE-2026-68878
HIGH 8.0
Windows Fast FAT Driver Elevation of Privilege Vulnerability |
|
CVE-2026-68880
HIGH 8.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-68894
HIGH 8.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69271
HIGH 8.0
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69301
HIGH 8.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69346
HIGH 8.0
Windows Print Spooler Components Elevation of Privilege Vulnerability |
|
CVE-2026-69365
HIGH 8.0
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2026-69418
HIGH 8.0
Volume Manager Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69427
HIGH 8.0
Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability |
|
CVE-2026-69458
HIGH 8.0
Windows BitLocker Elevation of Privilege Vulnerability |
|
CVE-2026-69462
HIGH 8.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69512
HIGH 8.0
Windows Spaceport.sys Elevation of Privilege Vulnerability |
|
CVE-2026-69714
HIGH 8.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69762
HIGH 8.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69807
HIGH 8.0
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2026-50502
HIGH 8.0
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. |
|
CVE-2026-50365
HIGH 8.0
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. |
|
CVE-2026-42975
HIGH 8.0
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. |
|
CVE-2026-40400
HIGH 8.0
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. |
|
CVE-2026-25172
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25173
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-26111
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-6726
HIGH 7.9
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a cred… |
|
CVE-2026-48575
HIGH 7.9
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-48576
HIGH 7.9
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-48578
HIGH 7.9
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-48568
HIGH 7.9
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-48570
HIGH 7.9
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-48573
HIGH 7.9
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-47656
HIGH 7.9
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-45654
HIGH 7.9
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-45588
HIGH 7.9
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-84000
HIGH 7.8
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally. |
|
CVE-2026-83987
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83988
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83990
HIGH 7.8
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83979
HIGH 7.8
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83980
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83981
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83982
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83983
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83985
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83974
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83976
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83977
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83978
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83968
HIGH 7.8
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83969
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83970
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83971
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83972
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83973
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83952
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83954
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83955
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83967
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83498
HIGH 7.8
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83942
HIGH 7.8
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80075
HIGH 7.8
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78448
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77904
HIGH 7.8
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77500
HIGH 7.8
Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77489
HIGH 7.8
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73024
HIGH 7.8
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73026
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73020
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73021
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73011
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73014
HIGH 7.8
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73015
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73007
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72997
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73000
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73001
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73002
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72992
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72993
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72994
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72995
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72996
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72990
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72991
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72988
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72965
HIGH 7.8
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72967
HIGH 7.8
Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72953
HIGH 7.8
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72941
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72944
HIGH 7.8
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72946
HIGH 7.8
Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72929
HIGH 7.8
Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71343
HIGH 7.8
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally. |
|
CVE-2026-71345
HIGH 7.8
Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. |
|
CVE-2026-71334
HIGH 7.8
Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71337
HIGH 7.8
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70574
HIGH 7.8
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70581
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70569
HIGH 7.8
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70572
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70564
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70289
HIGH 7.8
Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69921
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69907
HIGH 7.8
Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69900
HIGH 7.8
Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69864
HIGH 7.8
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69841
HIGH 7.8
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69844
HIGH 7.8
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69822
HIGH 7.8
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69787
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69738
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69720
HIGH 7.8
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69707
HIGH 7.8
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69709
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-69691
HIGH 7.8
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69685
HIGH 7.8
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69687
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69612
HIGH 7.8
Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69604
HIGH 7.8
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69608
HIGH 7.8
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69589
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69592
HIGH 7.8
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69593
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69594
HIGH 7.8
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69583
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69584
HIGH 7.8
Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69585
HIGH 7.8
Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69580
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69582
HIGH 7.8
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69571
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69532
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69513
HIGH 7.8
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69489
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69475
HIGH 7.8
Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69476
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69467
HIGH 7.8
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69456
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69450
HIGH 7.8
Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69426
HIGH 7.8
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally. |
|
CVE-2026-69420
HIGH 7.8
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69421
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69407
HIGH 7.8
Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69391
HIGH 7.8
Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69352
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69348
HIGH 7.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69323
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69312
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69307
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69298
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69293
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69295
HIGH 7.8
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69284
HIGH 7.8
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69270
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69265
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68892
HIGH 7.8
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68875
HIGH 7.8
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-68848
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68844
HIGH 7.8
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. |
|
CVE-2026-68845
HIGH 7.8
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68841
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68832
HIGH 7.8
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62697
HIGH 7.8
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56172
HIGH 7.8
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56177
HIGH 7.8
Use after free in Windows Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56198
HIGH 7.8
Microsoft Trace Data Helper Elevation of Privilege Vulnerability |
|
CVE-2026-62810
HIGH 7.8
Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability |
|
CVE-2026-68877
HIGH 7.8
Windows Storage Spaces Controller Remote Code Execution Vulnerability |
|
CVE-2026-68885
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-68888
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-68890
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-68896
HIGH 7.8
Microsoft Windows Search Component Elevation of Privilege Vulnerability |
|
CVE-2026-69269
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69277
HIGH 7.8
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2026-69283
HIGH 7.8
Windows CD-ROM Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69289
HIGH 7.8
Windows Setup Files Cleanup Elevation of Privilege Vulnerability |
|
CVE-2026-69290
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2026-69324
HIGH 7.8
Windows Performance Monitor Elevation of Privilege Vulnerability |
|
CVE-2026-69328
HIGH 7.8
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2026-69359
HIGH 7.8
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-69368
HIGH 7.8
Windows Overlay Filter Elevation of Privilege Vulnerability |
|
CVE-2026-69377
HIGH 7.8
Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
|
CVE-2026-69389
HIGH 7.8
Windows Storage Management Provider Elevation of Privilege Vulnerability |
|
CVE-2026-69392
HIGH 7.8
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2026-69424
HIGH 7.8
Windows Distributed File System (DFS) Elevation of Privilege Vulnerability |
|
CVE-2026-69432
HIGH 7.8
Volume Manager Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69433
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69436
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69444
HIGH 7.8
Microsoft Windows Speech Elevation of Privilege Vulnerability |
|
CVE-2026-69445
HIGH 7.8
Windows Compressed Folder Elevation of Privilege Vulnerability |
|
CVE-2026-69447
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69455
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2026-69459
HIGH 7.8
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2026-69478
HIGH 7.8
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69480
HIGH 7.8
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69508
HIGH 7.8
Windows MIDI Service Module Elevation of Privileges Vulnerability |
|
CVE-2026-69509
HIGH 7.8
Role: Windows Fax Service Elevation of Privilege Vulnerability |
|
CVE-2026-69528
HIGH 7.8
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2026-69534
HIGH 7.8
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
|
CVE-2026-69535
HIGH 7.8
Windows Spaceport.sys Elevation of Privilege Vulnerability |
|
CVE-2026-69538
HIGH 7.8
Windows Spaceport.sys Remote Code Execution Vulnerability |
|
CVE-2026-69541
HIGH 7.8
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69542
HIGH 7.8
Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability |
|
CVE-2026-69544
HIGH 7.8
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2026-69561
HIGH 7.8
Windows CD-ROM Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69576
HIGH 7.8
Graphic Fonts Elevation of Privilege Vulnerability |
|
CVE-2026-69725
CRITICAL 7.8
Windows Hello Elevation of Privilege Vulnerability |
|
CVE-2026-69731
HIGH 7.8
HID Class Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69758
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-69785
HIGH 7.8
Windows Smart Card Elevation of Privilege Vulnerability |
|
CVE-2026-69790
HIGH 7.8
Windows Credential Providers Elevation of Privilege Vulnerability |
|
CVE-2026-69799
CRITICAL 7.8
Windows Hello Elevation of Privilege Vulnerability |
|
CVE-2026-69801
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-70583
HIGH 7.8
Windows Core Messaging Elevation of Privilege Vulnerability |
|
CVE-2026-70584
HIGH 7.8
Windows Core Messaging Elevation of Privilege Vulnerability |
|
CVE-2026-78447
HIGH 7.8
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83975
HIGH 7.8
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83986
HIGH 7.8
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83995
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-70346
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70347
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70344
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70345
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-66799
HIGH 7.8
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-66804
HIGH 7.8
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65814
HIGH 7.8
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65786
HIGH 7.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65787
HIGH 7.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65790
HIGH 7.8
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65773
HIGH 7.8
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65774
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65775
HIGH 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65671
HIGH 7.8
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65672
HIGH 7.8
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62894
HIGH 7.8
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62888
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62890
HIGH 7.8
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. |
|
CVE-2026-62885
HIGH 7.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62876
HIGH 7.8
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62877
HIGH 7.8
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62880
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62832
HIGH 7.8
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62799
HIGH 7.8
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62811
HIGH 7.8
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62797
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62779
HIGH 7.8
Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62783
HIGH 7.8
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62777
HIGH 7.8
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62768
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62770
HIGH 7.8
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62771
HIGH 7.8
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62772
HIGH 7.8
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62754
HIGH 7.8
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62755
HIGH 7.8
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62758
HIGH 7.8
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62751
HIGH 7.8
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62752
HIGH 7.8
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62741
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62747
HIGH 7.8
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62735
HIGH 7.8
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62736
HIGH 7.8
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62737
HIGH 7.8
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62739
HIGH 7.8
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62732
HIGH 7.8
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62733
HIGH 7.8
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62722
HIGH 7.8
Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62717
HIGH 7.8
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62719
HIGH 7.8
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62721
HIGH 7.8
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62711
HIGH 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62712
HIGH 7.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62713
HIGH 7.8
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62707
HIGH 7.8
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62710
HIGH 7.8
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62696
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62698
HIGH 7.8
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62700
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62701
HIGH 7.8
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62688
HIGH 7.8
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62692
HIGH 7.8
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62695
HIGH 7.8
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61937
HIGH 7.8
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61934
HIGH 7.8
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61925
HIGH 7.8
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61926
HIGH 7.8
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61930
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61923
HIGH 7.8
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61367
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61364
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61365
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61355
HIGH 7.8
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61356
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61357
HIGH 7.8
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61358
HIGH 7.8
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate … |
|
CVE-2026-61359
HIGH 7.8
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61349
HIGH 7.8
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61353
HIGH 7.8
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59127
HIGH 7.8
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54984
HIGH 7.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-42976
HIGH 7.8
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58632
HIGH 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58633
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58634
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58613
HIGH 7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58628
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele… |
|
CVE-2026-58542
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58538
HIGH 7.8
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58540
HIGH 7.8
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58541
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58532
HIGH 7.8
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58536
HIGH 7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58537
HIGH 7.8
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58527
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-58530
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-57096
HIGH 7.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57091
HIGH 7.8
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56650
HIGH 7.8
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56643
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56644
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56189
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-56182
HIGH 7.8
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56175
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56176
HIGH 7.8
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54124
HIGH 7.8
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54125
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-54115
HIGH 7.8
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50689
HIGH 7.8
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50688
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50677
HIGH 7.8
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50679
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50673
HIGH 7.8
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50676
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50667
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges… |
|
CVE-2026-50655
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50509
HIGH 7.8
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50501
HIGH 7.8
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50498
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-50499
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50493
HIGH 7.8
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50494
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50484
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50486
HIGH 7.8
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50476
HIGH 7.8
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50478
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50469
HIGH 7.8
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50471
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50461
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50462
HIGH 7.8
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50466
HIGH 7.8
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50454
HIGH 7.8
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50457
HIGH 7.8
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50458
HIGH 7.8
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50448
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50450
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized … |
|
CVE-2026-50440
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate p… |
|
CVE-2026-50441
HIGH 7.8
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50433
HIGH 7.8
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50435
HIGH 7.8
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50436
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50427
HIGH 7.8
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50421
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv… |
|
CVE-2026-50422
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50423
HIGH 7.8
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50425
HIGH 7.8
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50412
HIGH 7.8
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50417
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50405
HIGH 7.8
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50407
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50399
HIGH 7.8
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50400
HIGH 7.8
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50402
HIGH 7.8
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50391
HIGH 7.8
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50386
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50387
HIGH 7.8
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50388
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50378
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi… |
|
CVE-2026-50373
HIGH 7.8
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50367
HIGH 7.8
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50361
HIGH 7.8
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50362
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50363
HIGH 7.8
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50353
HIGH 7.8
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50357
HIGH 7.8
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-50344
HIGH 7.8
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50346
HIGH 7.8
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50347
HIGH 7.8
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50336
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50337
HIGH 7.8
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50343
HIGH 7.8
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50331
HIGH 7.8
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50332
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50335
HIGH 7.8
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50326
HIGH 7.8
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50327
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. |
|
CVE-2026-50329
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50315
HIGH 7.8
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50317
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to eleva… |
|
CVE-2026-50321
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv… |
|
CVE-2026-50309
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50313
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50305
HIGH 7.8
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50306
HIGH 7.8
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58609
HIGH 7.8
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58610
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58635
HIGH 7.8
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privil… |
|
CVE-2026-58601
HIGH 7.8
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58602
HIGH 7.8
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-55004
HIGH 7.8
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54993
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54986
HIGH 7.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54987
HIGH 7.8
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54991
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-54112
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… |
|
CVE-2026-54114
HIGH 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54109
HIGH 7.8
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-50697
HIGH 7.8
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50351
HIGH 7.8
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50311
HIGH 7.8
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50318
HIGH 7.8
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50333
HIGH 7.8
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50308
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49808
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileg… |
|
CVE-2026-50293
HIGH 7.8
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49800
HIGH 7.8
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49793
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-49796
HIGH 7.8
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49797
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49792
HIGH 7.8
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-49783
HIGH 7.8
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-49173
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49175
HIGH 7.8
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49176
HIGH 7.8
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49166
HIGH 7.8
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49170
HIGH 7.8
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42982
HIGH 7.8
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44800
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-8863
HIGH 7.8
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo… |
|
CVE-2026-48574
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-48583
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45658
HIGH 7.8
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-45656
HIGH 7.8
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-45636
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-45637
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45638
HIGH 7.8
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45605
HIGH 7.8
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45600
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45592
HIGH 7.8
Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45593
HIGH 7.8
Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45586
HIGH 7.8
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileg… |
|
CVE-2026-45487
HIGH 7.8
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44811
HIGH 7.8
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44812
HIGH 7.8
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
|
CVE-2026-44813
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44802
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44803
HIGH 7.8
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
|
CVE-2026-44804
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44807
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44808
HIGH 7.8
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44809
HIGH 7.8
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42989
HIGH 7.8
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42991
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-42983
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42986
HIGH 7.8
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42977
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-42978
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-42979
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-42980
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42916
HIGH 7.8
Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42905
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42910
HIGH 7.8
Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42829
HIGH 7.8
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-42837
HIGH 7.8
Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42828
HIGH 7.8
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40404
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-40409
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-41092
HIGH 7.8
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33828
HIGH 7.8
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-41088
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-40397
HIGH 7.8
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40399
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg… |
|
CVE-2026-40369
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-35417
HIGH 7.8
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-34336
HIGH 7.8
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33840
HIGH 7.8
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33841
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-34330
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… |
|
CVE-2026-33834
HIGH 7.8
Windows Event Logging Service Elevation of Privilege Vulnerability |
|
CVE-2026-33835
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-33837
HIGH 7.8
Windows TCP/IP Local Elevation of Privilege Vulnerability |
|
CVE-2026-33838
HIGH 7.8
Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2026-34333
HIGH 7.8
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-34334
HIGH 7.8
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-34337
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-34338
HIGH 7.8
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-34343
HIGH 7.8
Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability |
|
CVE-2026-34344
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-34351
HIGH 7.8
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-35415
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2026-35418
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-35421
CRITICAL 7.8
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-40377
HIGH 7.8
Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
|
CVE-2026-40382
HIGH 7.8
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-40398
HIGH 7.8
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-40407
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2026-40408
HIGH 7.8
Windows WAN ARP Driver Elevation of Privilege Vulnerability |
|
CVE-2026-42896
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2026-33101
HIGH 7.8
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33098
HIGH 7.8
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32222
HIGH 7.8
Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32154
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32152
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32153
HIGH 7.8
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-26153
HIGH 7.8
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability |
|
CVE-2026-26156
HIGH 7.8
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-26159
HIGH 7.8
Remote Desktop Licensing Service Elevation of Privilege Vulnerability |
|
CVE-2026-26160
HIGH 7.8
Remote Desktop Licensing Service Elevation of Privilege Vulnerability |
|
CVE-2026-26161
HIGH 7.8
Windows Sensor Data Service Elevation of Privilege Vulnerability |
|
CVE-2026-26162
HIGH 7.8
Windows OLE Elevation of Privilege Vulnerability |
|
CVE-2026-26163
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-26168
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-26170
HIGH 7.8
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2026-26172
HIGH 7.8
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-26176
HIGH 7.8
Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability |
|
CVE-2026-26179
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-26180
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-26181
HIGH 7.8
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-26184
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-27907
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2026-27909
HIGH 7.8
Windows Search Service Elevation of Privilege Vulnerability |
|
CVE-2026-27910
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-27911
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-27914
HIGH 7.8
Microsoft Management Console Elevation of Privilege Vulnerability |
|
CVE-2026-27915
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2026-27916
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2026-27918
HIGH 7.8
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2026-27919
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2026-27920
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2026-27923
HIGH 7.8
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-27927
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-32069
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-32074
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-32076
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2026-32077
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2026-32078
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-32089
HIGH 7.8
Windows Speech Brokered Api Elevation of Privilege Vulnerability |
|
CVE-2026-32090
HIGH 7.8
Windows Speech Brokered Api Elevation of Privilege Vulnerability |
|
CVE-2026-32158
HIGH 7.8
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-32159
HIGH 7.8
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-32160
HIGH 7.8
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-32163
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32164
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32165
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32183
HIGH 7.8
Windows Snipping Tool Remote Code Execution Vulnerability |
|
CVE-2026-24293
HIGH 7.8
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24294
HIGH 7.8
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24289
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-23672
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-23673
HIGH 7.8
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
|
CVE-2026-24287
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-24290
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-24291
HIGH 7.8
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
|
CVE-2026-24292
HIGH 7.8
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-25165
HIGH 7.8
Performance Counters for Windows Elevation of Privilege Vulnerability |
|
CVE-2026-25174
HIGH 7.8
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability |
|
CVE-2026-25176
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25187
HIGH 7.8
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2026-25190
HIGH 7.8
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-26128
HIGH 7.8
Windows SMB Server Elevation of Privilege Vulnerability |
|
CVE-2026-26132
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21231
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21232
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21236
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21238
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21240
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21245
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21250
Exploit
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-73017
HIGH 7.5
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. |
|
CVE-2026-72949
HIGH 7.5
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-72932
HIGH 7.5
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-71330
HIGH 7.5
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to dis… |
|
CVE-2026-70587
HIGH 7.5
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69881
HIGH 7.5
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69890
HIGH 7.5
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69852
HIGH 7.5
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-69760
HIGH 7.5
Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69599
HIGH 7.5
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69588
HIGH 7.5
Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69587
HIGH 7.5
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69539
HIGH 7.5
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69514
HIGH 7.5
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69428
HIGH 7.5
Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-68887
HIGH 7.5
Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-62759
HIGH 7.5
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-62813
HIGH 7.5
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
|
CVE-2026-69329
HIGH 7.5
BranchCache Denial of Service Vulnerability |
|
CVE-2026-69397
HIGH 7.5
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
|
CVE-2026-69429
HIGH 7.5
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability |
|
CVE-2026-69710
CRITICAL 7.5
Windows Hello Elevation of Privilege Vulnerability |
|
CVE-2026-69793
HIGH 7.5
Windows TCP/IP Security Feature Bypass Vulnerability |
|
CVE-2026-69809
HIGH 7.5
Windows Active Directory Domain Services Denial of Service Vulnerability |
|
CVE-2026-70570
HIGH 7.5
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-70579
HIGH 7.5
Windows Mobile Broadband Information Disclosure Vulnerability |
|
CVE-2026-81355
CRITICAL 7.5
Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability |
|
CVE-2026-83989
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability |
|
CVE-2026-84001
HIGH 7.5
Windows Key Distribution Center Denial of Service Vulnerability |
|
CVE-2026-61363
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-61352
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… |
|
CVE-2026-59132
HIGH 7.5
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-59134
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-54113
HIGH 7.5
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-58531
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges … |
|
CVE-2026-57089
HIGH 7.5
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56648
HIGH 7.5
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50647
HIGH 7.5
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n… |
|
CVE-2026-50505
HIGH 7.5
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. |
|
CVE-2026-50496
HIGH 7.5
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50500
HIGH 7.5
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50470
HIGH 7.5
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50463
HIGH 7.5
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50424
HIGH 7.5
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50414
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50411
HIGH 7.5
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50379
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50330
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-54983
HIGH 7.5
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-54119
HIGH 7.5
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50695
HIGH 7.5
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50696
HIGH 7.5
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-49787
HIGH 7.5
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-49788
HIGH 7.5
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-49171
HIGH 7.5
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40378
HIGH 7.5
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over … |
|
CVE-2026-49160
HIGH 7.5
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-48563
HIGH 7.5
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-45639
HIGH 7.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-42992
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42993
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-44799
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-44801
HIGH 7.5
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42913
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… |
|
CVE-2026-42908
HIGH 7.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-42909
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… |
|
CVE-2026-32161
CRITICAL 7.5
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability |
|
CVE-2026-35424
HIGH 7.5
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
|
CVE-2026-40405
HIGH 7.5
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-40406
HIGH 7.5
Windows TCP/IP Information Disclosure Vulnerability |
|
CVE-2026-33096
HIGH 7.5
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-32071
HIGH 7.5
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
|
CVE-2026-23674
HIGH 7.5
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2026-25181
HIGH 7.5
GDI+ Information Disclosure Vulnerability |
|
CVE-2026-20846
HIGH 7.5
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
|
CVE-2025-21330
HIGH 7.5
Windows Remote Desktop Services Denial of Service Vulnerability |
|
CVE-2024-49075
HIGH 7.5
Windows Remote Desktop Services Denial of Service Vulnerability |
|
CVE-2026-69347
HIGH 7.4
Windows Fast FAT Driver Remote Code Execution Vulnerability |
|
CVE-2026-54127
HIGH 7.4
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-40413
HIGH 7.4
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-40414
HIGH 7.4
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-32156
HIGH 7.4
Windows UPnP Device Host Remote Code Execution Vulnerability |
|
CVE-2026-25167
HIGH 7.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-50482
HIGH 7.3
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-58640
HIGH 7.3
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50364
HIGH 7.3
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49789
HIGH 7.3
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49790
HIGH 7.3
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-32149
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21235
HIGH 7.3
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21244
Exploit
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21247
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21248
Exploit
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-69688
HIGH 7.1
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69602
HIGH 7.1
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69597
HIGH 7.1
Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69536
HIGH 7.1
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69482
HIGH 7.1
Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69460
HIGH 7.1
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69396
HIGH 7.1
Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69366
HIGH 7.1
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69340
HIGH 7.1
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69313
HIGH 7.1
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69314
HIGH 7.1
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69305
HIGH 7.1
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69296
HIGH 7.1
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68889
HIGH 7.1
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68846
HIGH 7.1
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68835
HIGH 7.1
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69272
HIGH 7.1
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69274
HIGH 7.1
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69336
HIGH 7.1
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69337
HIGH 7.1
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2026-69358
HIGH 7.1
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69364
HIGH 7.1
Windows Print Spooler Components Elevation of Privilege Vulnerability |
|
CVE-2026-69384
HIGH 7.1
Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability |
|
CVE-2026-69451
HIGH 7.1
Windows Management Instrumentation Elevation of Privilege Vulnerability |
|
CVE-2026-69553
HIGH 7.1
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-69706
HIGH 7.1
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69757
HIGH 7.1
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-69761
HIGH 7.1
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-58529
HIGH 7.1
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. |
|
CVE-2026-50682
HIGH 7.1
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. |
|
CVE-2026-50465
HIGH 7.1
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-50451
HIGH 7.1
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50428
HIGH 7.1
Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-55144
HIGH 7.1
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. |
|
CVE-2026-50354
HIGH 7.1
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49791
HIGH 7.1
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri… |
|
CVE-2026-49165
HIGH 7.1
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. |
|
CVE-2026-40401
HIGH 7.1
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-26151
HIGH 7.1
Remote Desktop Spoofing Vulnerability |
|
CVE-2025-64720
HIGH 7.1
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication |
|
CVE-2025-65018
HIGH 7.1
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` |
|
CVE-2026-83999
HIGH 7.0
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to e… |
|
CVE-2026-83940
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80093
HIGH 7.0
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78457
HIGH 7.0
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78464
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77899
HIGH 7.0
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77905
HIGH 7.0
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77894
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privi… |
|
CVE-2026-73022
HIGH 7.0
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73005
HIGH 7.0
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73003
HIGH 7.0
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72963
HIGH 7.0
Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72952
HIGH 7.0
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. |
|
CVE-2026-72930
HIGH 7.0
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally. |
|
CVE-2026-71353
HIGH 7.0
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72926
HIGH 7.0
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71351
HIGH 7.0
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71342
HIGH 7.0
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71340
HIGH 7.0
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71332
HIGH 7.0
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71333
HIGH 7.0
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70573
HIGH 7.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70577
HIGH 7.0
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70565
HIGH 7.0
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70567
HIGH 7.0
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70568
HIGH 7.0
Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70562
HIGH 7.0
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70283
HIGH 7.0
Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69911
HIGH 7.0
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69891
HIGH 7.0
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69896
HIGH 7.0
Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69889
HIGH 7.0
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69859
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69866
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69834
HIGH 7.0
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69838
HIGH 7.0
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69816
HIGH 7.0
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69817
HIGH 7.0
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69818
HIGH 7.0
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69814
HIGH 7.0
Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69791
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69692
HIGH 7.0
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69693
HIGH 7.0
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69694
HIGH 7.0
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69682
HIGH 7.0
Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69648
HIGH 7.0
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69645
HIGH 7.0
Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69630
HIGH 7.0
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69621
HIGH 7.0
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69617
HIGH 7.0
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69610
HIGH 7.0
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69613
HIGH 7.0
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69605
HIGH 7.0
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69606
HIGH 7.0
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69600
HIGH 7.0
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69578
HIGH 7.0
Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69581
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69573
HIGH 7.0
Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69574
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69575
HIGH 7.0
Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69567
HIGH 7.0
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69501
HIGH 7.0
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69470
HIGH 7.0
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69472
HIGH 7.0
Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69473
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69466
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69430
HIGH 7.0
Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69422
HIGH 7.0
Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69413
HIGH 7.0
Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69404
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg… |
|
CVE-2026-69379
HIGH 7.0
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69333
HIGH 7.0
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69319
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevat… |
|
CVE-2026-69310
HIGH 7.0
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69299
HIGH 7.0
Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69287
HIGH 7.0
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69281
HIGH 7.0
Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68897
HIGH 7.0
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68884
HIGH 7.0
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68847
HIGH 7.0
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68837
HIGH 7.0
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68840
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv… |
|
CVE-2026-68824
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an autho… |
|
CVE-2026-68825
HIGH 7.0
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62694
HIGH 7.0
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50349
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… |
|
CVE-2026-69275
HIGH 7.0
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69279
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69280
HIGH 7.0
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-69300
HIGH 7.0
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-69309
HIGH 7.0
Windows Print Spooler Components Elevation of Privilege Vulnerability |
|
CVE-2026-69311
HIGH 7.0
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69331
HIGH 7.0
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2026-69335
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69341
HIGH 7.0
Windows Image Acquisition Elevation of Privilege Vulnerability |
|
CVE-2026-69362
HIGH 7.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69383
HIGH 7.0
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2026-69385
HIGH 7.0
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-69388
HIGH 7.0
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2026-69394
HIGH 7.0
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69398
HIGH 7.0
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2026-69401
HIGH 7.0
Audio Video Control Transport Protocol Elevation of Privilege Vulnerability |
|
CVE-2026-69440
HIGH 7.0
Windows MIDI Service Module Elevation of Privileges Vulnerability |
|
CVE-2026-69441
HIGH 7.0
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-69448
HIGH 7.0
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2026-69468
HIGH 7.0
Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69488
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69492
HIGH 7.0
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69498
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69500
HIGH 7.0
Windows Image Acquisition Elevation of Privilege Vulnerability |
|
CVE-2026-69516
HIGH 7.0
Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability |
|
CVE-2026-69517
HIGH 7.0
Windows Wireless Networking Elevation of Privilege Vulnerability |
|
CVE-2026-69540
HIGH 7.0
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69549
HIGH 7.0
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69560
HIGH 7.0
Windows Work Folder Service Elevation of Privilege Vulnerability |
|
CVE-2026-69563
HIGH 7.0
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
|
CVE-2026-69611
HIGH 7.0
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69652
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69654
HIGH 7.0
Windows Accounts Control Elevation of Privilege Vulnerability |
|
CVE-2026-69708
HIGH 7.0
Windows Web Platform Storage Elevation of Privilege Vulnerability |
|
CVE-2026-69711
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69735
HIGH 7.0
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
|
CVE-2026-69779
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-70578
HIGH 7.0
Windows Credential Guard Elevation of Privilege Vulnerability |
|
CVE-2026-85360
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-62727
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-70307
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65788
HIGH 7.0
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65779
HIGH 7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65780
HIGH 7.0
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65776
HIGH 7.0
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65678
HIGH 7.0
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62908
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p… |
|
CVE-2026-62892
HIGH 7.0
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62788
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62780
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62773
HIGH 7.0
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62774
HIGH 7.0
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62766
HIGH 7.0
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62748
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-62749
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62753
HIGH 7.0
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62729
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-62734
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-62723
HIGH 7.0
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62724
HIGH 7.0
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62725
HIGH 7.0
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62726
HIGH 7.0
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62728
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62705
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elev… |
|
CVE-2026-61939
HIGH 7.0
Use after free in Winlogon allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62690
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-62693
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to ele… |
|
CVE-2026-61938
HIGH 7.0
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61927
HIGH 7.0
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61929
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61366
HIGH 7.0
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61361
HIGH 7.0
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. |
|
CVE-2026-61348
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61346
HIGH 7.0
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59122
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-59125
HIGH 7.0
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59126
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e… |
|
CVE-2026-50472
HIGH 7.0
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58598
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p… |
|
CVE-2026-58629
HIGH 7.0
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58637
HIGH 7.0
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58619
HIGH 7.0
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58544
HIGH 7.0
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57093
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56183
HIGH 7.0
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56187
HIGH 7.0
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56173
HIGH 7.0
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50672
HIGH 7.0
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50674
HIGH 7.0
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50669
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-50503
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50490
HIGH 7.0
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50491
HIGH 7.0
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50459
HIGH 7.0
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-50449
HIGH 7.0
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50452
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… |
|
CVE-2026-50406
HIGH 7.0
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50410
HIGH 7.0
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50403
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50404
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50392
HIGH 7.0
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50393
HIGH 7.0
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50396
HIGH 7.0
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50397
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50390
HIGH 7.0
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50371
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege… |
|
CVE-2026-50372
HIGH 7.0
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50359
HIGH 7.0
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50358
HIGH 7.0
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50345
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50348
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… |
|
CVE-2026-50322
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50307
HIGH 7.0
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58526
HIGH 7.0
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54996
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-54989
HIGH 7.0
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54129
HIGH 7.0
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54111
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-50384
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate pr… |
|
CVE-2026-50356
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… |
|
CVE-2026-50323
HIGH 7.0
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50325
HIGH 7.0
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50297
HIGH 7.0
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49806
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-50296
HIGH 7.0
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49802
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-49803
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to… |
|
CVE-2026-49805
HIGH 7.0
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49183
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat… |
|
CVE-2026-49784
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… |
|
CVE-2026-48571
HIGH 7.0
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-48572
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p… |
|
CVE-2026-49162
HIGH 7.0
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-47648
HIGH 7.0
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45653
HIGH 7.0
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45640
HIGH 7.0
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45598
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… |
|
CVE-2026-45601
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… |
|
CVE-2026-45603
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… |
|
CVE-2026-45596
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45597
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized atta… |
|
CVE-2026-42984
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42911
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42912
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-42836
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized atta… |
|
CVE-2026-41108
HIGH 7.0
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-34335
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-54518
HIGH 7.0
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif… |
|
CVE-2026-35416
HIGH 7.0
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-34345
HIGH 7.0
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-33839
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-34331
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-34340
HIGH 7.0
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-34341
HIGH 7.0
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability |
|
CVE-2026-34342
HIGH 7.0
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2026-34347
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-40410
HIGH 7.0
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2026-42825
HIGH 7.0
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-33104
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… |
|
CVE-2026-33100
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32224
HIGH 7.0
Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-25184
HIGH 7.0
Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability |
|
CVE-2026-26152
HIGH 7.0
Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
|
CVE-2026-26165
HIGH 7.0
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2026-26166
HIGH 7.0
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2026-26173
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-26174
HIGH 7.0
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
|
CVE-2026-26177
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-26182
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-27908
HIGH 7.0
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability |
|
CVE-2026-27917
HIGH 7.0
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability |
|
CVE-2026-27921
HIGH 7.0
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability |
|
CVE-2026-27922
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-27926
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-27929
HIGH 7.0
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-32068
HIGH 7.0
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
|
CVE-2026-32070
HIGH 7.0
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2026-32073
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-32075
HIGH 7.0
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2026-32082
HIGH 7.0
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
|
CVE-2026-32083
HIGH 7.0
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
|
CVE-2026-32086
HIGH 7.0
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
|
CVE-2026-32087
HIGH 7.0
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
|
CVE-2026-32093
HIGH 7.0
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
|
CVE-2026-32150
HIGH 7.0
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
|
CVE-2026-32195
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-32219
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-23667
HIGH 7.0
Broadcast DVR Elevation of Privilege Vulnerability |
|
CVE-2026-23671
HIGH 7.0
Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability |
|
CVE-2026-24295
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-24296
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-25170
HIGH 7.0
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-25171
HIGH 7.0
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2026-25178
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25179
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21234
HIGH 7.0
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-21237
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21241
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21242
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21253
HIGH 7.0
Mailslot File System Elevation of Privilege Vulnerability |
|
CVE-2026-21508
HIGH 7.0
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2020-17103
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-78451
MEDIUM 6.8
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-77892
MEDIUM 6.8
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72999
MEDIUM 6.8
Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72985
MEDIUM 6.8
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-71350
MEDIUM 6.8
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-71348
MEDIUM 6.8
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-71349
MEDIUM 6.8
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-71329
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-69566
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-69490
MEDIUM 6.8
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-68833
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-62702
MEDIUM 6.8
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-62699
MEDIUM 6.8
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-58528
MEDIUM 6.8
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-50668
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50492
MEDIUM 6.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-54132
MEDIUM 6.8
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50298
MEDIUM 6.8
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50299
MEDIUM 6.8
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-49168
MEDIUM 6.8
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50507
MEDIUM 6.8
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-45608
MEDIUM 6.8
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-45585
MEDIUM 6.8
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… |
|
CVE-2026-32223
MEDIUM 6.8
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72935
MEDIUM 6.7
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71339
MEDIUM 6.7
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69350
HIGH 6.7
Windows Overlay Filter Elevation of Privilege Vulnerability |
|
CVE-2026-69373
HIGH 6.7
Windows Overlay Filter Elevation of Privilege Vulnerability |
|
CVE-2026-69449
HIGH 6.7
Windows BitLocker Remote Code Execution Vulnerability |
|
CVE-2026-72927
HIGH 6.7
Winsock Elevation of Privilege Vulnerability |
|
CVE-2026-70330
MEDIUM 6.7
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70304
MEDIUM 6.7
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65799
MEDIUM 6.7
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65795
MEDIUM 6.7
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65797
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65798
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62881
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62883
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62769
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32170
MEDIUM 6.7
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-21530
HIGH 6.7
Windows Rich Text Edit Elevation of Privilege Vulnerability |
|
CVE-2026-41097
HIGH 6.7
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2026-69469
MEDIUM 6.6
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-61920
MEDIUM 6.6
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a… |
|
CVE-2025-2884
MEDIUM 6.6
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with… |
|
CVE-2026-78453
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-72942
MEDIUM 6.5
Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-72939
MEDIUM 6.5
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-70019
MEDIUM 6.5
Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69781
MEDIUM 6.5
Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. |
|
CVE-2026-69374
MEDIUM 6.5
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network. |
|
CVE-2026-68898
MEDIUM 6.5
Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69267
MEDIUM 6.5
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. |
|
CVE-2026-62801
MEDIUM 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security featu… |
|
CVE-2026-62762
HIGH 6.5
Windows Active Directory Domain Services Denial of Service Vulnerability |
|
CVE-2026-77896
HIGH 6.5
Windows Remote Desktop Client Denial of Service Vulnerability |
|
CVE-2026-65794
MEDIUM 6.5
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-65785
MEDIUM 6.5
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. |
|
CVE-2026-62782
MEDIUM 6.5
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-62750
MEDIUM 6.5
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. |
|
CVE-2026-61921
MEDIUM 6.5
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-61924
MEDIUM 6.5
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-61918
MEDIUM 6.5
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-59138
MEDIUM 6.5
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-61345
MEDIUM 6.5
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-58546
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-58539
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-58533
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-58535
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-57982
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. |
|
CVE-2026-56168
MEDIUM 6.5
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. |
|
CVE-2026-54126
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50504
MEDIUM 6.5
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50497
MEDIUM 6.5
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50445
MEDIUM 6.5
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50376
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50366
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-57976
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-57979
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-55003
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-49799
MEDIUM 6.5
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-34348
MEDIUM 6.5
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-42907
MEDIUM 6.5
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. |
|
CVE-2026-42903
MEDIUM 6.5
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-35422
HIGH 6.5
Windows TCP/IP Driver Security Feature Bypass Vulnerability |
|
CVE-2026-26155
HIGH 6.5
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
|
CVE-2026-27925
HIGH 6.5
Windows UPnP Device Host Information Disclosure Vulnerability |
|
CVE-2026-32151
HIGH 6.5
Windows Shell Information Disclosure Vulnerability |
|
CVE-2026-72947
MEDIUM 6.4
Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70582
HIGH 6.4
Windows Management Instrumentation Elevation of Privilege Vulnerability |
|
CVE-2026-62708
MEDIUM 6.4
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-57097
MEDIUM 6.4
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-55000
MEDIUM 6.4
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-58543
MEDIUM 6.3
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-50374
MEDIUM 6.3
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50375
MEDIUM 6.3
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57095
MEDIUM 6.2
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-50420
MEDIUM 6.2
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-49807
MEDIUM 6.2
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-50294
MEDIUM 6.2
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-40380
HIGH 6.2
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability |
|
CVE-2026-32072
HIGH 6.2
Active Directory Spoofing Vulnerability |
|
CVE-2026-25168
HIGH 6.2
Windows Graphics Component Denial of Service Vulnerability |
|
CVE-2026-25169
HIGH 6.2
Windows Graphics Component Denial of Service Vulnerability |
|
CVE-2026-50661
MEDIUM 6.1
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-50495
MEDIUM 6.1
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-50453
MEDIUM 6.1
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-50383
MEDIUM 6.1
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
|
CVE-2026-49174
MEDIUM 6.1
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-26169
HIGH 6.1
Windows Kernel Memory Information Disclosure Vulnerability |
|
CVE-2026-32088
HIGH 6.1
Windows Biometric Service Security Feature Bypass Vulnerability |
|
CVE-2026-25250
MEDIUM 6.0
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable." |
|
CVE-2026-58638
MEDIUM 6.0
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-6727
MEDIUM 5.9
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may … |
|
CVE-2026-56649
MEDIUM 5.9
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e… |
|
CVE-2026-69723
MEDIUM 5.7
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a netwo… |
|
CVE-2026-69591
MEDIUM 5.7
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69569
MEDIUM 5.7
Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. |
|
CVE-2026-69572
MEDIUM 5.7
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69552
MEDIUM 5.7
Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a n… |
|
CVE-2026-69507
MEDIUM 5.7
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose… |
|
CVE-2026-69393
MEDIUM 5.7
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69349
MEDIUM 5.7
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. |
|
CVE-2026-68874
MEDIUM 5.7
Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69317
HIGH 5.7
Windows Remote Desktop Client Information Disclosure Vulnerability |
|
CVE-2026-23670
HIGH 5.7
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
|
CVE-2026-69832
MEDIUM 5.6
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-59130
MEDIUM 5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
|
CVE-2026-59131
MEDIUM 5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
|
CVE-2026-83501
MEDIUM 5.5
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
|
CVE-2026-78454
MEDIUM 5.5
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-77491
MEDIUM 5.5
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-73004
MEDIUM 5.5
Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally. |
|
CVE-2026-73008
MEDIUM 5.5
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-72964
MEDIUM 5.5
Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally. |
|
CVE-2026-72966
MEDIUM 5.5
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. |
|
CVE-2026-71341
MEDIUM 5.5
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-70290
MEDIUM 5.5
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. |
|
CVE-2026-70145
MEDIUM 5.5
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-69862
MEDIUM 5.5
Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-69808
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69770
MEDIUM 5.5
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69741
MEDIUM 5.5
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69684
MEDIUM 5.5
Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. |
|
CVE-2026-69674
MEDIUM 5.5
Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-69627
MEDIUM 5.5
Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-69616
MEDIUM 5.5
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-69618
MEDIUM 5.5
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. |
|
CVE-2026-69609
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69568
MEDIUM 5.5
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. |
|
CVE-2026-69554
MEDIUM 5.5
Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69527
MEDIUM 5.5
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-69504
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69457
MEDIUM 5.5
Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-69406
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-69403
MEDIUM 5.5
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. |
|
CVE-2026-69390
MEDIUM 5.5
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69351
MEDIUM 5.5
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclo… |
|
CVE-2026-69353
MEDIUM 5.5
Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. |
|
CVE-2026-69344
MEDIUM 5.5
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
|
CVE-2026-69339
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information… |
|
CVE-2026-69343
MEDIUM 5.5
Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-69318
MEDIUM 5.5
Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-69315
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information loc… |
|
CVE-2026-69294
MEDIUM 5.5
Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
|
CVE-2026-69286
MEDIUM 5.5
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-69288
MEDIUM 5.5
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
|
CVE-2026-68886
MEDIUM 5.5
Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. |
|
CVE-2026-68873
MEDIUM 5.5
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information local… |
|
CVE-2026-68851
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-68842
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information… |
|
CVE-2026-68831
MEDIUM 5.5
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-68830
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose … |
|
CVE-2026-68843
HIGH 5.5
Microsoft Office Word Information Disclosure Vulnerability |
|
CVE-2026-68852
HIGH 5.5
Microsoft Account Information Disclosure Vulnerability |
|
CVE-2026-68881
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-68895
HIGH 5.5
Internet Storage Name Service Information Disclosure Vulnerability |
|
CVE-2026-69303
HIGH 5.5
Push Message Routing Service Information Disclosure Vulnerability |
|
CVE-2026-69308
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69321
HIGH 5.5
Windows Power Dependency Coordinator Tampering Vulnerability |
|
CVE-2026-69345
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69367
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69376
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69453
HIGH 5.5
Microsoft Windows Search Component Tampering Vulnerability |
|
CVE-2026-69531
HIGH 5.5
Microsoft Windows Speech Tampering Vulnerability |
|
CVE-2026-69794
HIGH 5.5
Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
|
CVE-2026-72937
HIGH 5.5
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2026-77492
HIGH 5.5
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2026-83991
HIGH 5.5
Windows Cloud Files Mini Filter Driver Tampering Vulnerability |
|
CVE-2026-72971
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to p… |
|
CVE-2026-70348
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. |
|
CVE-2026-65784
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-65662
MEDIUM 5.5
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. |
|
CVE-2026-62887
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-62798
MEDIUM 5.5
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62793
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-62796
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-62786
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62775
MEDIUM 5.5
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-62743
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62746
MEDIUM 5.5
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62738
MEDIUM 5.5
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. |
|
CVE-2026-62740
MEDIUM 5.5
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-62730
MEDIUM 5.5
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-62703
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-62709
MEDIUM 5.5
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
|
CVE-2026-61936
MEDIUM 5.5
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-61933
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-61928
MEDIUM 5.5
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
|
CVE-2026-61360
MEDIUM 5.5
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
|
CVE-2026-61347
MEDIUM 5.5
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-59136
MEDIUM 5.5
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
|
CVE-2026-59137
MEDIUM 5.5
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-59135
MEDIUM 5.5
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-59128
MEDIUM 5.5
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. |
|
CVE-2026-58545
MEDIUM 5.5
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-58547
MEDIUM 5.5
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57083
MEDIUM 5.5
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-57084
MEDIUM 5.5
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-57085
MEDIUM 5.5
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
|
CVE-2026-56184
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-50690
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-50681
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-50483
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-50475
MEDIUM 5.5
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50473
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50455
MEDIUM 5.5
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. |
|
CVE-2026-50456
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50442
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50434
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-50437
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-50430
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-50431
MEDIUM 5.5
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability |
|
CVE-2026-50409
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-50401
MEDIUM 5.5
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-50394
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-50389
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50377
MEDIUM 5.5
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50352
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-50339
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-50341
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-50334
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. |
|
CVE-2026-49177
MEDIUM 5.5
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. |
|
CVE-2026-58614
MEDIUM 5.5
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-54997
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-50381
MEDIUM 5.5
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local… |
|
CVE-2026-50350
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo… |
|
CVE-2026-50316
MEDIUM 5.5
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50300
MEDIUM 5.5
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50303
MEDIUM 5.5
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-50295
MEDIUM 5.5
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-49801
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-49180
MEDIUM 5.5
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca… |
|
CVE-2026-40422
MEDIUM 5.5
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-41087
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-33842
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34328
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-34346
MEDIUM 5.5
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. |
|
CVE-2026-34349
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-48566
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-45604
MEDIUM 5.5
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. |
|
CVE-2026-45606
MEDIUM 5.5
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. |
|
CVE-2026-45634
MEDIUM 5.5
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
|
CVE-2026-45594
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat… |
|
CVE-2026-44814
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-42973
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42968
MEDIUM 5.5
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-42969
MEDIUM 5.5
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42970
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42971
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42972
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-42915
MEDIUM 5.5
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. |
|
CVE-2026-42906
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. |
|
CVE-2026-34339
HIGH 5.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2026-35419
HIGH 5.5
Windows DWM Core Library Information Disclosure Vulnerability |
|
CVE-2026-20806
HIGH 5.5
Windows COM Server Information Disclosure Vulnerability |
|
CVE-2026-27930
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2026-27931
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2026-32079
HIGH 5.5
Web Account Manager Information Disclosure Vulnerability |
|
CVE-2026-32081
HIGH 5.5
Package Catalog Information Disclosure Vulnerability |
|
CVE-2026-32084
HIGH 5.5
Windows Print Spooler Information Disclosure Vulnerability |
|
CVE-2026-32085
HIGH 5.5
Remote Procedure Call Information Disclosure Vulnerability |
|
CVE-2026-32181
HIGH 5.5
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
|
CVE-2026-32212
HIGH 5.5
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
|
CVE-2026-32214
HIGH 5.5
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
|
CVE-2026-32215
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32216
HIGH 5.5
Windows Redirected Drive Buffering System Denial of Service Vulnerability |
|
CVE-2026-32217
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32218
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-25180
HIGH 5.5
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-24282
HIGH 5.5
Push message Routing Service Elevation of Privilege Vulnerability |
|
CVE-2026-25186
HIGH 5.5
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability |
|
CVE-2026-45595
MEDIUM 5.4
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-35423
HIGH 5.4
Windows 11 Telnet Client Information Disclosure Vulnerability |
|
CVE-2026-78446
MEDIUM 5.3
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-70575
HIGH 5.3
Windows Schannel Denial of Service Vulnerability |
|
CVE-2026-65777
MEDIUM 5.3
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. |
|
CVE-2026-62757
MEDIUM 5.3
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-50432
MEDIUM 5.3
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. |
|
CVE-2026-50415
MEDIUM 5.3
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-44806
MEDIUM 5.3
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-45655
MEDIUM 5.3
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-42914
MEDIUM 5.3
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-25185
HIGH 5.3
Windows Shell Link Processing Spoofing Vulnerability |
|
CVE-2026-50418
MEDIUM 5.1
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2026-61368
MEDIUM 5.0
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-69474
MEDIUM 4.8
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. |
|
CVE-2026-72931
MEDIUM 4.7
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally. |
|
CVE-2026-69895
MEDIUM 4.7
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69853
MEDIUM 4.7
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69483
MEDIUM 4.7
Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. |
|
CVE-2026-69425
MEDIUM 4.7
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69316
MEDIUM 4.7
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-68849
MEDIUM 4.7
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-68891
HIGH 4.7
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69771
HIGH 4.7
Windows Container Manager Service Security Feature Bypass Vulnerability |
|
CVE-2026-69792
HIGH 4.7
Windows Win32K Security Feature Bypass Vulnerability |
|
CVE-2026-50310
MEDIUM 4.7
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. |
|
CVE-2026-50312
MEDIUM 4.7
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49167
MEDIUM 4.7
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78508
MEDIUM 4.6
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78452
MEDIUM 4.6
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-69548
MEDIUM 4.6
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-69381
MEDIUM 4.6
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-61350
MEDIUM 4.6
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-49794
MEDIUM 4.6
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-20928
HIGH 4.6
Windows Recovery Environment Security Feature Bypass Vulnerability |
|
CVE-2026-26175
HIGH 4.6
Windows Boot Manager Security Feature Bypass Vulnerability |
|
CVE-2026-50485
MEDIUM 4.5
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
|
CVE-2026-72980
MEDIUM 4.4
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-69713
HIGH 4.4
Windows Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2026-32209
HIGH 4.4
Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability |
|
CVE-2026-32220
MEDIUM 4.4
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-27906
HIGH 4.4
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2026-78516
MEDIUM 4.3
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78455
MEDIUM 4.3
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-73019
MEDIUM 4.3
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-33829
Exploit
MEDIUM 4.3
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-50302
MEDIUM 4.2
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-45642
LOW 3.9
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a… |
|
CVE-2026-50419
LOW 3.3
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50416
LOW 3.3
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-21249
HIGH 3.3
Windows NTLM Spoofing Vulnerability |
Déployer ce correctif Windows sur votre flotte
Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.