Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Windows · Build corrective · Tous les builds Windows

10.0.19045.7417

Advisory MSRC

La build Windows 10.0.19045.7417, publiée le 2026-06-09, corrige 147 CVE, déployée sur 1 SKU.

Publiée le
2026-06-09
SKU couvertes
1
CVE corrigées
147

8 critique · 119 élevé

KEV CISA
0

SKU Windows couvertes par cette build

Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.

CVE corrigées par cette build

CVE
CVE-2026-47291
CRITICAL 9.8

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

CVE-2026-44815
CRITICAL 9.8

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42904
CRITICAL 9.6

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-45602
CRITICAL 9.1

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

CVE-2025-10263
CRITICAL 9.1

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C…

CVE-2026-47653
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47289
HIGH 8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42985
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-34329
HIGH 8.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2026-40403
CRITICAL 8.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2026-45641
HIGH 8.4

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-45607
HIGH 8.4

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-45635
HIGH 8.1

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a netw…

CVE-2026-45599
HIGH 8.1

Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

CVE-2026-40415
HIGH 8.1

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2026-48575
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48576
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48578
HIGH 7.9

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

CVE-2026-48568
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48570
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48573
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-47656
HIGH 7.9

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

CVE-2026-45588
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-8863
HIGH 7.8

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo…

CVE-2026-48583
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-48574
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-45658
HIGH 7.8

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

CVE-2026-45656
HIGH 7.8

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

CVE-2026-45636
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-45638
HIGH 7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45637
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-45605
HIGH 7.8

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-45592
HIGH 7.8

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-45593
HIGH 7.8

Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

CVE-2026-45586
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileg…

CVE-2026-45487
HIGH 7.8

Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-44812
HIGH 7.8

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2026-44802
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-44803
HIGH 7.8

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2026-42991
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42989
HIGH 7.8

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-42986
HIGH 7.8

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-42983
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-42980
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42978
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42977
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42979
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42916
HIGH 7.8

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42905
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-42837
HIGH 7.8

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-42828
HIGH 7.8

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-40409
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-40404
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-41092
HIGH 7.8

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

CVE-2026-33828
HIGH 7.8

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

CVE-2026-41088
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-40399
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg…

CVE-2026-40397
HIGH 7.8

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-35417
HIGH 7.8

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-34336
HIGH 7.8

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-33841
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-34330
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33834
HIGH 7.8

Windows Event Logging Service Elevation of Privilege Vulnerability

CVE-2026-34333
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-34343
HIGH 7.8

Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability

CVE-2026-34344
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-34351
HIGH 7.8

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-35415
HIGH 7.8

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

CVE-2026-35418
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-35421
CRITICAL 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-40377
HIGH 7.8

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

CVE-2026-40407
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2026-40408
HIGH 7.8

Windows WAN ARP Driver Elevation of Privilege Vulnerability

CVE-2026-33835
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-33837
HIGH 7.8

Windows TCP/IP Local Elevation of Privilege Vulnerability

CVE-2026-33838
HIGH 7.8

Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability

CVE-2026-34334
HIGH 7.8

Windows TCP/IP Elevation of Privilege Vulnerability

CVE-2026-34337
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2026-34338
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-40382
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-40398
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-49160
HIGH 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-48563
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-45639
HIGH 7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-42992
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-44799
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-44801
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42993
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42908
HIGH 7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-42909
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute…

CVE-2026-35424
HIGH 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

CVE-2026-40406
HIGH 7.5

Windows TCP/IP Information Disclosure Vulnerability

CVE-2026-32161
CRITICAL 7.5

Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability

CVE-2026-40414
HIGH 7.4

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40413
HIGH 7.4

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40401
HIGH 7.1

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-47648
HIGH 7.0

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-45653
HIGH 7.0

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-45640
HIGH 7.0

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-45601
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-45598
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-45603
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-45596
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-42984
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-42911
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-42912
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-42836
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized atta…

CVE-2026-41108
HIGH 7.0

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-34335
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2025-54518
HIGH 7.0

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif…

CVE-2026-35416
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-34345
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-33839
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2026-34331
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2026-34342
HIGH 7.0

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2026-34347
HIGH 7.0

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-40410
HIGH 7.0

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2026-42825
HIGH 7.0

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-34340
HIGH 7.0

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-34341
HIGH 7.0

Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege Vulnerability

CVE-2026-50507
MEDIUM 6.8

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-45608
MEDIUM 6.8

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-32170
MEDIUM 6.7

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

CVE-2026-21530
HIGH 6.7

Windows Rich Text Edit Elevation of Privilege Vulnerability

CVE-2026-41097
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2026-42907
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVE-2026-42903
MEDIUM 6.5

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-35422
HIGH 6.5

Windows TCP/IP Driver Security Feature Bypass Vulnerability

CVE-2026-40380
HIGH 6.2

Windows Volume Manager Extension Driver Remote Code Execution Vulnerability

CVE-2026-45606
MEDIUM 5.5

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45634
MEDIUM 5.5

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

CVE-2026-45594
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat…

CVE-2026-42973
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42968
MEDIUM 5.5

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

CVE-2026-42972
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-42969
MEDIUM 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42971
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42970
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42915
MEDIUM 5.5

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

CVE-2026-42906
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

CVE-2026-34339
HIGH 5.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2026-45595
MEDIUM 5.4

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-35423
HIGH 5.4

Windows 11 Telnet Client Information Disclosure Vulnerability

CVE-2026-45655
MEDIUM 5.3

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-42914
MEDIUM 5.3

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-32209
HIGH 4.4

Windows Filtering Platform (WFP) Security Feature Bypass Vulnerability

CVE-2026-45642
LOW 3.9

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a…

Déployer ce correctif Windows sur votre flotte

Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.

Gérer Windows avec Appaloosa