Windows · Build corrective · Tous les builds Windows
10.0.22631.7376
Advisory MSRCLa build Windows 10.0.22631.7376, publiée le 2026-07-14, corrige 18 CVE, dont 1 activement exploitée (CISA KEV), déployée sur 1 SKU.
- Publiée le
- 2026-07-14
- SKU couvertes
- 1
- CVE corrigées
- 18
- KEV CISA
- 1
2 critique · 11 élevé
SKU Windows couvertes par cette build
Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.
CVE corrigées par cette build
| CVE |
|---|
|
CVE-2026-32202
MEDIUM 4.3
KEV
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-49172
CRITICAL 9.8
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42990
CRITICAL 9.8
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50471
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58601
HIGH 7.8
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42982
HIGH 7.8
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44800
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-50696
HIGH 7.5
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-40378
HIGH 7.5
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over … |
|
CVE-2026-58640
HIGH 7.3
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-58629
HIGH 7.0
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56173
HIGH 7.0
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-48572
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p… |
|
CVE-2026-48571
HIGH 7.0
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-34348
MEDIUM 6.5
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-34346
MEDIUM 5.5
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. |
|
CVE-2026-33842
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34328
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |
Déployer ce correctif Windows sur votre flotte
Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.