Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Windows · Build corrective · Tous les builds Windows

10.0.26100.7623

Advisory MSRC

La build Windows 10.0.26100.7623, publiée le 2026-01-13, corrige 86 CVE, dont 1 activement exploitée (CISA KEV), déployée sur 1 SKU.

Publiée le
2026-01-13
SKU couvertes
1
CVE corrigées
86

58 élevé

KEV CISA
1

SKU Windows couvertes par cette build

Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.

CVE corrigées par cette build

CVE
CVE-2026-20805
MEDIUM 5.5 KEV

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2026-20868
HIGH 8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2026-20856
HIGH 8.1

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVE-2026-20931
HIGH 8.0

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-20941
HIGH 7.8

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2026-20938
HIGH 7.8

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-20924
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20922
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20923
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20877
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20918
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20873
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20874
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20867
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20870
HIGH 7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20871
HIGH 7.8

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-20864
HIGH 7.8

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

CVE-2026-20865
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20861
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20866
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20857
HIGH 7.8

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20858
HIGH 7.8

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20859
HIGH 7.8

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-20860
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-20840
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20843
HIGH 7.8

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-20832
HIGH 7.8

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

CVE-2026-20837
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-20826
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an autho…

CVE-2026-20831
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-20820
HIGH 7.8

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20822
HIGH 7.8

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-20816
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-20817
HIGH 7.8

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-20809
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVE-2026-20811
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2023-31096
HIGH 7.8

MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability

CVE-2024-55414
HIGH 7.8

Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability

CVE-2026-20852
HIGH 7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

CVE-2026-20804
HIGH 7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

CVE-2025-6965
HIGH 7.7

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead…

CVE-2026-20934
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20926
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20919
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20921
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20875
HIGH 7.5

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVE-2026-20854
HIGH 7.5

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

CVE-2026-20848
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20849
HIGH 7.5

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

CVE-2026-20853
HIGH 7.4

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate…

CVE-2026-20844
HIGH 7.4

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

CVE-2026-21221
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20869
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacke…

CVE-2026-20863
HIGH 7.0

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20842
HIGH 7.0

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-20836
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile…

CVE-2026-20814
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile…

CVE-2026-20815
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20808
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elev…

CVE-2026-20876
MEDIUM 6.7

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-20925
MEDIUM 6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20872
MEDIUM 6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20847
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

CVE-2026-20812
MEDIUM 6.5

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

CVE-2026-21265
MEDIUM 6.4

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect…

CVE-2026-20935
MEDIUM 6.2

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

CVE-2026-20851
MEDIUM 6.2

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

CVE-2026-20821
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

CVE-2026-20939
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20932
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20937
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20862
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

CVE-2026-20838
MEDIUM 5.5

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-20839
MEDIUM 5.5

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

CVE-2026-20835
MEDIUM 5.5

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

CVE-2026-20827
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform…

CVE-2026-20829
MEDIUM 5.5

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

CVE-2026-20823
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20824
MEDIUM 5.5

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-20819
MEDIUM 5.5

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

CVE-2026-20927
MEDIUM 5.3

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service…

CVE-2026-20834
MEDIUM 4.6

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

CVE-2026-20828
MEDIUM 4.6

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-20962
MEDIUM 4.4

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

CVE-2026-20825
MEDIUM 4.4

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-20936
MEDIUM 4.3

Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.

Déployer ce correctif Windows sur votre flotte

Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.

Gérer Windows avec Appaloosa