Windows · Build corrective · Tous les builds Windows
10.0.17763.9245
Advisory MSRCLa build Windows 10.0.17763.9245, publiée le 2026-09-08, corrige 616 CVE, dont 1 activement exploitée (CISA KEV), déployée sur 3 SKU.
- Publiée le
- 2026-09-08
- SKU couvertes
- 3
- CVE corrigées
- 616
- KEV CISA
- 1
33 critique · 481 élevé
SKU Windows couvertes par cette build
Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.
CVE corrigées par cette build
| CVE |
|---|
|
CVE-2026-85880
HIGH 7.8
KEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
|
CVE-2026-78445
CRITICAL 9.8
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-77493
CRITICAL 9.8
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73025
CRITICAL 9.8
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-73009
CRITICAL 9.8
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73010
CRITICAL 9.8
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72983
CRITICAL 9.8
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72979
CRITICAL 9.8
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72982
CRITICAL 9.8
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70296
CRITICAL 9.8
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69910
CRITICAL 9.8
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69845
CRITICAL 9.8
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69824
CRITICAL 9.8
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69829
CRITICAL 9.8
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69768
CRITICAL 9.8
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69730
CRITICAL 9.8
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69715
CRITICAL 9.8
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69595
CRITICAL 9.8
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69590
CRITICAL 9.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-69586
CRITICAL 9.8
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69579
CRITICAL 9.8
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69525
CRITICAL 9.8
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69496
CRITICAL 9.8
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69491
CRITICAL 9.8
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69463
CRITICAL 9.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69431
CRITICAL 9.8
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-68839
CRITICAL 9.8
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69276
HIGH 9.8
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability |
|
CVE-2026-69408
HIGH 9.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-69493
HIGH 9.8
Windows Event Logging Service Remote Code Execution Vulnerability |
|
CVE-2026-69769
CRITICAL 9.8
Windows HTTP Print Provider Remote Code Execution Vulnerability |
|
CVE-2026-69819
HIGH 9.8
RPC Runtime Library Remote Code Execution Vulnerability |
|
CVE-2026-83992
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-81955
HIGH 8.8
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-80096
HIGH 8.8
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-77495
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73023
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73012
HIGH 8.8
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-73013
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73016
HIGH 8.8
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73006
HIGH 8.8
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72986
HIGH 8.8
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72959
HIGH 8.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-72960
HIGH 8.8
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72950
HIGH 8.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-71352
HIGH 8.8
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network. |
|
CVE-2026-71336
HIGH 8.8
Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network. |
|
CVE-2026-70586
HIGH 8.8
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70203
HIGH 8.8
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69860
HIGH 8.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69676
HIGH 8.8
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network. |
|
CVE-2026-69669
HIGH 8.8
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69628
HIGH 8.8
Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network. |
|
CVE-2026-69603
HIGH 8.8
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. |
|
CVE-2026-69598
HIGH 8.8
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69601
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69547
HIGH 8.8
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. |
|
CVE-2026-69551
HIGH 8.8
Use after free in Windows DNS allows an authorized attacker to execute code over a network. |
|
CVE-2026-69518
HIGH 8.8
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69499
HIGH 8.8
Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69461
HIGH 8.8
Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69291
HIGH 8.8
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62706
HIGH 8.8
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-68828
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69266
HIGH 8.8
Windows DHCP Server Remote Code Execution Vulnerability |
|
CVE-2026-69334
HIGH 8.8
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability |
|
CVE-2026-69360
HIGH 8.8
Microsoft Office Word Remote Code Execution Vulnerability |
|
CVE-2026-69386
HIGH 8.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-69434
HIGH 8.8
Windows URL Moniker Remote Code Execution Vulnerability |
|
CVE-2026-69485
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69494
HIGH 8.8
Windows Event Logging Service Remote Code Execution Vulnerability |
|
CVE-2026-69495
HIGH 8.8
Windows Event Logging Service Remote Code Execution Vulnerability |
|
CVE-2026-69511
HIGH 8.8
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-69712
CRITICAL 8.8
Windows Key Distribution Center Remote Code Execution Vulnerability |
|
CVE-2026-69772
HIGH 8.8
Windows Network File System Remote Code Execution Vulnerability |
|
CVE-2026-72933
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability |
|
CVE-2026-73018
CRITICAL 8.8
Graphic Fonts Remote Code Execution Vulnerability |
|
CVE-2026-77504
CRITICAL 8.8
Microsoft Office Word Remote Code Execution Vulnerability |
|
CVE-2026-83996
HIGH 8.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-83998
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69638
HIGH 8.4
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-69479
HIGH 8.4
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-77503
HIGH 8.4
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-81354
HIGH 8.2
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72962
HIGH 8.2
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72961
HIGH 8.2
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69906
HIGH 8.2
Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69874
HIGH 8.2
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69846
HIGH 8.2
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78450
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78444
HIGH 8.1
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78449
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72987
HIGH 8.1
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72981
HIGH 8.1
Use after free in IP Helper allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70563
HIGH 8.1
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-70342
HIGH 8.1
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-69989
HIGH 8.1
Use after free in DNS Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69827
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over … |
|
CVE-2026-69813
HIGH 8.1
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69680
HIGH 8.1
Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-69620
HIGH 8.1
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69438
HIGH 8.1
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69325
HIGH 8.1
Microsoft JScript Remote Code Execution Vulnerability |
|
CVE-2026-69510
HIGH 8.1
Windows DHCP Server Remote Code Execution Vulnerability |
|
CVE-2026-69524
HIGH 8.1
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
|
CVE-2026-69530
CRITICAL 8.1
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
|
CVE-2026-69546
HIGH 8.1
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
|
CVE-2026-69732
HIGH 8.1
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability |
|
CVE-2026-69782
HIGH 8.1
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2026-69786
HIGH 8.1
Windows Text Shaping Remote Code Execution Vulnerability |
|
CVE-2026-77505
CRITICAL 8.1
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2026-69875
HIGH 8.0
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69876
HIGH 8.0
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. |
|
CVE-2026-69847
HIGH 8.0
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. |
|
CVE-2026-69826
HIGH 8.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69773
HIGH 8.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69727
HIGH 8.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69717
HIGH 8.0
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69689
HIGH 8.0
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69681
HIGH 8.0
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69643
HIGH 8.0
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69623
HIGH 8.0
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network. |
|
CVE-2026-69625
HIGH 8.0
Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69619
HIGH 8.0
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69503
HIGH 8.0
Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69505
HIGH 8.0
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69481
HIGH 8.0
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69423
HIGH 8.0
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69371
HIGH 8.0
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69332
HIGH 8.0
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68838
HIGH 8.0
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68834
HIGH 8.0
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68827
HIGH 8.0
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68876
HIGH 8.0
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
|
CVE-2026-68878
HIGH 8.0
Windows Fast FAT Driver Elevation of Privilege Vulnerability |
|
CVE-2026-68880
HIGH 8.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-68894
HIGH 8.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69271
HIGH 8.0
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69301
HIGH 8.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69346
HIGH 8.0
Windows Print Spooler Components Elevation of Privilege Vulnerability |
|
CVE-2026-69412
HIGH 8.0
Windows DHCP Server Remote Code Execution Vulnerability |
|
CVE-2026-69418
HIGH 8.0
Volume Manager Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69427
HIGH 8.0
Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability |
|
CVE-2026-69458
HIGH 8.0
Windows BitLocker Elevation of Privilege Vulnerability |
|
CVE-2026-69462
HIGH 8.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69512
HIGH 8.0
Windows Spaceport.sys Elevation of Privilege Vulnerability |
|
CVE-2026-69714
HIGH 8.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69762
HIGH 8.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69807
HIGH 8.0
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2026-84000
HIGH 7.8
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally. |
|
CVE-2026-83987
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83988
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83979
HIGH 7.8
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83980
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83981
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83982
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83983
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83985
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83974
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83976
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83977
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83978
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83968
HIGH 7.8
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83969
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83970
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83971
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83972
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83973
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83954
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83955
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83967
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-83942
HIGH 7.8
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80075
HIGH 7.8
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78448
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77904
HIGH 7.8
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77500
HIGH 7.8
Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77489
HIGH 7.8
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73024
HIGH 7.8
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73026
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73020
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73021
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73011
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73014
HIGH 7.8
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73015
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73007
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72997
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73000
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73001
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73002
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72992
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72993
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72994
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72995
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72996
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72990
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72991
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72988
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72965
HIGH 7.8
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72967
HIGH 7.8
Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72957
HIGH 7.8
Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally. |
|
CVE-2026-72941
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72944
HIGH 7.8
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71343
HIGH 7.8
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally. |
|
CVE-2026-71345
HIGH 7.8
Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally. |
|
CVE-2026-71334
HIGH 7.8
Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70574
HIGH 7.8
Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70581
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70572
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70564
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70289
HIGH 7.8
Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69907
HIGH 7.8
Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69841
HIGH 7.8
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69844
HIGH 7.8
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69822
HIGH 7.8
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69787
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69738
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69707
HIGH 7.8
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69709
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-69691
HIGH 7.8
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69685
HIGH 7.8
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69687
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69612
HIGH 7.8
Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69604
HIGH 7.8
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69608
HIGH 7.8
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69589
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69592
HIGH 7.8
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69593
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69583
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69584
HIGH 7.8
Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69585
HIGH 7.8
Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69580
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69582
HIGH 7.8
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69571
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69532
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69513
HIGH 7.8
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69489
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69475
HIGH 7.8
Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69476
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69456
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69450
HIGH 7.8
Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69426
HIGH 7.8
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally. |
|
CVE-2026-69420
HIGH 7.8
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69421
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69407
HIGH 7.8
Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69391
HIGH 7.8
Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69352
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69323
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69312
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69307
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69298
HIGH 7.8
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69293
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69295
HIGH 7.8
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69284
HIGH 7.8
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69270
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69265
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68892
HIGH 7.8
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68875
HIGH 7.8
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-68848
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68844
HIGH 7.8
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. |
|
CVE-2026-68845
HIGH 7.8
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68841
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68832
HIGH 7.8
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56172
HIGH 7.8
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56177
HIGH 7.8
Use after free in Windows Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62810
HIGH 7.8
Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability |
|
CVE-2026-68877
HIGH 7.8
Windows Storage Spaces Controller Remote Code Execution Vulnerability |
|
CVE-2026-68885
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-68888
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-68890
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69269
HIGH 7.8
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69277
HIGH 7.8
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2026-69283
HIGH 7.8
Windows CD-ROM Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69289
HIGH 7.8
Windows Setup Files Cleanup Elevation of Privilege Vulnerability |
|
CVE-2026-69290
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2026-69324
HIGH 7.8
Windows Performance Monitor Elevation of Privilege Vulnerability |
|
CVE-2026-69328
HIGH 7.8
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2026-69359
HIGH 7.8
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-69368
HIGH 7.8
Windows Overlay Filter Elevation of Privilege Vulnerability |
|
CVE-2026-69377
HIGH 7.8
Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
|
CVE-2026-69389
HIGH 7.8
Windows Storage Management Provider Elevation of Privilege Vulnerability |
|
CVE-2026-69424
HIGH 7.8
Windows Distributed File System (DFS) Elevation of Privilege Vulnerability |
|
CVE-2026-69432
HIGH 7.8
Volume Manager Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69433
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69436
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69444
HIGH 7.8
Microsoft Windows Speech Elevation of Privilege Vulnerability |
|
CVE-2026-69445
HIGH 7.8
Windows Compressed Folder Elevation of Privilege Vulnerability |
|
CVE-2026-69455
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2026-69459
HIGH 7.8
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2026-69478
HIGH 7.8
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69509
HIGH 7.8
Role: Windows Fax Service Elevation of Privilege Vulnerability |
|
CVE-2026-69534
HIGH 7.8
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
|
CVE-2026-69538
HIGH 7.8
Windows Spaceport.sys Remote Code Execution Vulnerability |
|
CVE-2026-69541
HIGH 7.8
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69561
HIGH 7.8
Windows CD-ROM Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69576
HIGH 7.8
Graphic Fonts Elevation of Privilege Vulnerability |
|
CVE-2026-69731
HIGH 7.8
HID Class Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69758
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-69785
HIGH 7.8
Windows Smart Card Elevation of Privilege Vulnerability |
|
CVE-2026-69790
HIGH 7.8
Windows Credential Providers Elevation of Privilege Vulnerability |
|
CVE-2026-69801
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69821
HIGH 7.8
Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability |
|
CVE-2026-70583
HIGH 7.8
Windows Core Messaging Elevation of Privilege Vulnerability |
|
CVE-2026-70584
HIGH 7.8
Windows Core Messaging Elevation of Privilege Vulnerability |
|
CVE-2026-78447
HIGH 7.8
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83975
HIGH 7.8
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83986
HIGH 7.8
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83995
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-77893
HIGH 7.5
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77895
HIGH 7.5
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77886
HIGH 7.5
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77888
HIGH 7.5
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77889
HIGH 7.5
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77890
HIGH 7.5
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77501
HIGH 7.5
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77502
HIGH 7.5
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77498
HIGH 7.5
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77499
HIGH 7.5
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-77494
HIGH 7.5
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-73017
HIGH 7.5
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. |
|
CVE-2026-72989
HIGH 7.5
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-72954
HIGH 7.5
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-72943
HIGH 7.5
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-72932
HIGH 7.5
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-71330
HIGH 7.5
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to dis… |
|
CVE-2026-70587
HIGH 7.5
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-70065
HIGH 7.5
Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69881
HIGH 7.5
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69890
HIGH 7.5
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69852
HIGH 7.5
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-69760
HIGH 7.5
Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69631
HIGH 7.5
Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69607
HIGH 7.5
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69539
HIGH 7.5
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69514
HIGH 7.5
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69443
HIGH 7.5
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69428
HIGH 7.5
Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-68887
HIGH 7.5
Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-62759
HIGH 7.5
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-62813
HIGH 7.5
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
|
CVE-2026-69329
HIGH 7.5
BranchCache Denial of Service Vulnerability |
|
CVE-2026-69342
HIGH 7.5
Windows DHCP Server Denial of Service Vulnerability |
|
CVE-2026-69397
HIGH 7.5
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
|
CVE-2026-69429
HIGH 7.5
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability |
|
CVE-2026-69793
HIGH 7.5
Windows TCP/IP Security Feature Bypass Vulnerability |
|
CVE-2026-70570
HIGH 7.5
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-81355
CRITICAL 7.5
Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability |
|
CVE-2026-83989
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability |
|
CVE-2026-84001
HIGH 7.5
Windows Key Distribution Center Denial of Service Vulnerability |
|
CVE-2026-69347
HIGH 7.4
Windows Fast FAT Driver Remote Code Execution Vulnerability |
|
CVE-2026-69688
HIGH 7.1
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69602
HIGH 7.1
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69482
HIGH 7.1
Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69460
HIGH 7.1
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69396
HIGH 7.1
Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69366
HIGH 7.1
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69340
HIGH 7.1
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69313
HIGH 7.1
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69314
HIGH 7.1
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69305
HIGH 7.1
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69296
HIGH 7.1
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68893
HIGH 7.1
Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68889
HIGH 7.1
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68846
HIGH 7.1
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68835
HIGH 7.1
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69272
HIGH 7.1
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69274
HIGH 7.1
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69336
HIGH 7.1
Microsoft Standard XPS Elevation of Privilege Vulnerability |
|
CVE-2026-69337
HIGH 7.1
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2026-69338
HIGH 7.1
Remote Desktop Gateway Service Elevation of Privilege Vulnerability |
|
CVE-2026-69357
HIGH 7.1
Windows NDIS Elevation of Privilege Vulnerability |
|
CVE-2026-69358
HIGH 7.1
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69364
HIGH 7.1
Windows Print Spooler Components Elevation of Privilege Vulnerability |
|
CVE-2026-69384
HIGH 7.1
Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability |
|
CVE-2026-69451
HIGH 7.1
Windows Management Instrumentation Elevation of Privilege Vulnerability |
|
CVE-2026-69553
HIGH 7.1
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-69706
HIGH 7.1
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69757
HIGH 7.1
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-69761
HIGH 7.1
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-83940
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80093
HIGH 7.0
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77905
HIGH 7.0
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-77894
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privi… |
|
CVE-2026-73022
HIGH 7.0
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73005
HIGH 7.0
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-73003
HIGH 7.0
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72963
HIGH 7.0
Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72952
HIGH 7.0
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally. |
|
CVE-2026-72930
HIGH 7.0
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally. |
|
CVE-2026-71353
HIGH 7.0
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72926
HIGH 7.0
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71351
HIGH 7.0
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71342
HIGH 7.0
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71340
HIGH 7.0
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71332
HIGH 7.0
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71333
HIGH 7.0
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70585
HIGH 7.0
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally. |
|
CVE-2026-70573
HIGH 7.0
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70577
HIGH 7.0
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70565
HIGH 7.0
Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70568
HIGH 7.0
Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70562
HIGH 7.0
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70283
HIGH 7.0
Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69911
HIGH 7.0
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69891
HIGH 7.0
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69889
HIGH 7.0
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69859
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69866
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69834
HIGH 7.0
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69838
HIGH 7.0
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69816
HIGH 7.0
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69817
HIGH 7.0
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69791
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69692
HIGH 7.0
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69693
HIGH 7.0
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69694
HIGH 7.0
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69682
HIGH 7.0
Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69645
HIGH 7.0
Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69630
HIGH 7.0
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69621
HIGH 7.0
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69610
HIGH 7.0
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69613
HIGH 7.0
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69600
HIGH 7.0
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69578
HIGH 7.0
Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69581
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69573
HIGH 7.0
Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69574
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69575
HIGH 7.0
Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69567
HIGH 7.0
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69470
HIGH 7.0
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69472
HIGH 7.0
Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69473
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69466
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69430
HIGH 7.0
Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69413
HIGH 7.0
Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69404
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg… |
|
CVE-2026-69319
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevat… |
|
CVE-2026-69310
HIGH 7.0
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69287
HIGH 7.0
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69281
HIGH 7.0
Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68897
HIGH 7.0
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68884
HIGH 7.0
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68837
HIGH 7.0
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68840
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv… |
|
CVE-2026-62694
HIGH 7.0
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50349
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… |
|
CVE-2026-69275
HIGH 7.0
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69279
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69280
HIGH 7.0
Windows Push Notifications Elevation of Privilege Vulnerability |
|
CVE-2026-69292
HIGH 7.0
Remote Desktop Gateway Service Elevation of Privilege Vulnerability |
|
CVE-2026-69309
HIGH 7.0
Windows Print Spooler Components Elevation of Privilege Vulnerability |
|
CVE-2026-69311
HIGH 7.0
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69331
HIGH 7.0
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2026-69335
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69341
HIGH 7.0
Windows Image Acquisition Elevation of Privilege Vulnerability |
|
CVE-2026-69362
HIGH 7.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2026-69385
HIGH 7.0
Windows TCP/IP Elevation of Privilege Vulnerability |
|
CVE-2026-69388
HIGH 7.0
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2026-69394
HIGH 7.0
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69398
HIGH 7.0
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2026-69410
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69441
HIGH 7.0
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2026-69468
HIGH 7.0
Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69488
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69492
HIGH 7.0
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69498
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69500
HIGH 7.0
Windows Image Acquisition Elevation of Privilege Vulnerability |
|
CVE-2026-69516
HIGH 7.0
Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability |
|
CVE-2026-69517
HIGH 7.0
Windows Wireless Networking Elevation of Privilege Vulnerability |
|
CVE-2026-69540
HIGH 7.0
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2026-69549
HIGH 7.0
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69560
HIGH 7.0
Windows Work Folder Service Elevation of Privilege Vulnerability |
|
CVE-2026-69563
HIGH 7.0
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
|
CVE-2026-69564
HIGH 7.0
Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability |
|
CVE-2026-69611
HIGH 7.0
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69652
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69654
HIGH 7.0
Windows Accounts Control Elevation of Privilege Vulnerability |
|
CVE-2026-69708
HIGH 7.0
Windows Web Platform Storage Elevation of Privilege Vulnerability |
|
CVE-2026-69711
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69735
HIGH 7.0
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
|
CVE-2026-69779
HIGH 7.0
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-85360
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-78451
MEDIUM 6.8
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-77892
MEDIUM 6.8
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72999
MEDIUM 6.8
Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72985
MEDIUM 6.8
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-71350
MEDIUM 6.8
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-71348
MEDIUM 6.8
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-71349
MEDIUM 6.8
Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-71329
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-69566
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-69490
MEDIUM 6.8
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-69415
MEDIUM 6.8
Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68833
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-72948
MEDIUM 6.7
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-72935
MEDIUM 6.7
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71339
MEDIUM 6.7
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69350
HIGH 6.7
Windows Overlay Filter Elevation of Privilege Vulnerability |
|
CVE-2026-69373
HIGH 6.7
Windows Overlay Filter Elevation of Privilege Vulnerability |
|
CVE-2026-69449
HIGH 6.7
Windows BitLocker Remote Code Execution Vulnerability |
|
CVE-2026-72927
HIGH 6.7
Winsock Elevation of Privilege Vulnerability |
|
CVE-2026-69469
MEDIUM 6.6
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-78453
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-72942
MEDIUM 6.5
Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-72939
MEDIUM 6.5
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-69839
MEDIUM 6.5
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-69624
MEDIUM 6.5
Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network. |
|
CVE-2026-68898
MEDIUM 6.5
Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69267
MEDIUM 6.5
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. |
|
CVE-2026-62801
MEDIUM 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security featu… |
|
CVE-2026-62762
HIGH 6.5
Windows Active Directory Domain Services Denial of Service Vulnerability |
|
CVE-2026-69297
HIGH 6.5
Windows DHCP Server Information Disclosure Vulnerability |
|
CVE-2026-69395
HIGH 6.5
Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability |
|
CVE-2026-69497
HIGH 6.5
Windows DHCP Server Denial of Service Vulnerability |
|
CVE-2026-77896
HIGH 6.5
Windows Remote Desktop Client Denial of Service Vulnerability |
|
CVE-2026-77887
MEDIUM 6.4
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
|
CVE-2026-77891
MEDIUM 6.4
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
|
CVE-2026-72947
MEDIUM 6.4
Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-71338
MEDIUM 6.4
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69878
MEDIUM 6.4
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally. |
|
CVE-2026-70582
HIGH 6.4
Windows Management Instrumentation Elevation of Privilege Vulnerability |
|
CVE-2026-78523
MEDIUM 5.9
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-72978
MEDIUM 5.9
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a net… |
|
CVE-2026-70091
MEDIUM 5.9
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over… |
|
CVE-2026-70124
MEDIUM 5.9
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69929
MEDIUM 5.9
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69930
MEDIUM 5.9
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69803
MEDIUM 5.9
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-69723
MEDIUM 5.7
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a netwo… |
|
CVE-2026-69591
MEDIUM 5.7
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69569
MEDIUM 5.7
Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. |
|
CVE-2026-69572
MEDIUM 5.7
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69552
MEDIUM 5.7
Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a n… |
|
CVE-2026-69416
MEDIUM 5.7
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
|
CVE-2026-69393
MEDIUM 5.7
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69372
MEDIUM 5.7
Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. |
|
CVE-2026-69349
MEDIUM 5.7
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. |
|
CVE-2026-68874
MEDIUM 5.7
Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69317
HIGH 5.7
Windows Remote Desktop Client Information Disclosure Vulnerability |
|
CVE-2026-69405
HIGH 5.7
Windows DHCP Server Denial of Service Vulnerability |
|
CVE-2026-69637
HIGH 5.7
Windows DHCP Server Denial of Service Vulnerability |
|
CVE-2026-69679
HIGH 5.7
Windows DHCP Server Denial of Service Vulnerability |
|
CVE-2026-69832
MEDIUM 5.6
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-78454
MEDIUM 5.5
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-77491
MEDIUM 5.5
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-73008
MEDIUM 5.5
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-72964
MEDIUM 5.5
Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally. |
|
CVE-2026-72966
MEDIUM 5.5
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. |
|
CVE-2026-72945
MEDIUM 5.5
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. |
|
CVE-2026-71341
MEDIUM 5.5
Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-70290
MEDIUM 5.5
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. |
|
CVE-2026-70145
MEDIUM 5.5
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-69862
MEDIUM 5.5
Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-69808
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69770
MEDIUM 5.5
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69684
MEDIUM 5.5
Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. |
|
CVE-2026-69672
MEDIUM 5.5
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69674
MEDIUM 5.5
Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-69627
MEDIUM 5.5
Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-69616
MEDIUM 5.5
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-69618
MEDIUM 5.5
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. |
|
CVE-2026-69609
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69568
MEDIUM 5.5
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. |
|
CVE-2026-69554
MEDIUM 5.5
Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69527
MEDIUM 5.5
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-69504
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69457
MEDIUM 5.5
Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-69406
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-69403
MEDIUM 5.5
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. |
|
CVE-2026-69390
MEDIUM 5.5
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69369
MEDIUM 5.5
Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69351
MEDIUM 5.5
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclo… |
|
CVE-2026-69353
MEDIUM 5.5
Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. |
|
CVE-2026-69343
MEDIUM 5.5
Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-69318
MEDIUM 5.5
Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-69315
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information loc… |
|
CVE-2026-69294
MEDIUM 5.5
Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
|
CVE-2026-69286
MEDIUM 5.5
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-69288
MEDIUM 5.5
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
|
CVE-2026-68886
MEDIUM 5.5
Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. |
|
CVE-2026-68851
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-68831
MEDIUM 5.5
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-68830
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose … |
|
CVE-2026-68843
HIGH 5.5
Microsoft Office Word Information Disclosure Vulnerability |
|
CVE-2026-68852
HIGH 5.5
Microsoft Account Information Disclosure Vulnerability |
|
CVE-2026-68881
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-68895
HIGH 5.5
Internet Storage Name Service Information Disclosure Vulnerability |
|
CVE-2026-69303
HIGH 5.5
Push Message Routing Service Information Disclosure Vulnerability |
|
CVE-2026-69308
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69321
HIGH 5.5
Windows Power Dependency Coordinator Tampering Vulnerability |
|
CVE-2026-69345
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69367
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69376
HIGH 5.5
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69453
HIGH 5.5
Microsoft Windows Search Component Tampering Vulnerability |
|
CVE-2026-69531
HIGH 5.5
Microsoft Windows Speech Tampering Vulnerability |
|
CVE-2026-69794
HIGH 5.5
Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
|
CVE-2026-72937
HIGH 5.5
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2026-77492
HIGH 5.5
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2026-83991
HIGH 5.5
Windows Cloud Files Mini Filter Driver Tampering Vulnerability |
|
CVE-2026-78446
MEDIUM 5.3
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-69474
MEDIUM 4.8
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. |
|
CVE-2026-72931
MEDIUM 4.7
Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally. |
|
CVE-2026-69895
MEDIUM 4.7
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69853
MEDIUM 4.7
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69483
MEDIUM 4.7
Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. |
|
CVE-2026-69316
MEDIUM 4.7
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-68891
HIGH 4.7
Microsoft Standard XPS Information Disclosure Vulnerability |
|
CVE-2026-69792
HIGH 4.7
Windows Win32K Security Feature Bypass Vulnerability |
|
CVE-2026-78508
MEDIUM 4.6
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78452
MEDIUM 4.6
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-69548
MEDIUM 4.6
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-69381
MEDIUM 4.6
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-72980
MEDIUM 4.4
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-69713
HIGH 4.4
Windows Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2026-78516
MEDIUM 4.3
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78455
MEDIUM 4.3
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-73019
MEDIUM 4.3
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. |
Déployer ce correctif Windows sur votre flotte
Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.