Windows · Build corrective · Tous les builds Windows
10.0.28000.2525
Advisory MSRCLa build Windows 10.0.28000.2525, publiée le 2026-07-16, corrige 383 CVE, dont 1 activement exploitée (CISA KEV), déployée sur 1 SKU.
- Publiée le
- 2026-07-16
- SKU couvertes
- 1
- CVE corrigées
- 383
- KEV CISA
- 1
9 critique · 277 élevé
SKU Windows couvertes par cette build
Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.
CVE corrigées par cette build
| CVE |
|---|
|
CVE-2026-32202
MEDIUM 4.3
KEV
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-57092
CRITICAL 9.9
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56190
CRITICAL 9.8
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56188
CRITICAL 9.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to… |
|
CVE-2026-50447
CRITICAL 9.8
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-54990
CRITICAL 9.8
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-49172
CRITICAL 9.8
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42990
CRITICAL 9.8
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50380
CRITICAL 9.6
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-49798
CRITICAL 9.3
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-58626
HIGH 8.8
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-58594
HIGH 8.8
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-58534
HIGH 8.8
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57094
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57090
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57087
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56647
HIGH 8.8
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56194
HIGH 8.8
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50692
HIGH 8.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50687
HIGH 8.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50670
HIGH 8.8
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50666
HIGH 8.8
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50489
HIGH 8.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50474
HIGH 8.8
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50477
HIGH 8.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50413
HIGH 8.8
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50398
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50385
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50382
HIGH 8.8
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. |
|
CVE-2026-50369
HIGH 8.8
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50360
HIGH 8.8
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-58608
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker t… |
|
CVE-2026-54999
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… |
|
CVE-2026-54982
HIGH 8.8
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. |
|
CVE-2026-54107
HIGH 8.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… |
|
CVE-2026-50342
HIGH 8.8
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49795
HIGH 8.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49178
HIGH 8.8
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-50340
HIGH 8.5
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-54128
HIGH 8.4
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54992
HIGH 8.4
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54122
HIGH 8.4
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49184
HIGH 8.4
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-56181
HIGH 8.3
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-50680
HIGH 8.2
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50429
HIGH 8.2
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-56186
HIGH 8.1
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. |
|
CVE-2026-50686
HIGH 8.1
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50487
HIGH 8.1
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-50460
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… |
|
CVE-2026-50439
HIGH 8.1
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-54995
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-50694
HIGH 8.1
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-49164
HIGH 8.1
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42900
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri… |
|
CVE-2026-50502
HIGH 8.0
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. |
|
CVE-2026-50365
HIGH 8.0
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. |
|
CVE-2026-42975
HIGH 8.0
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. |
|
CVE-2026-40400
HIGH 8.0
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. |
|
CVE-2026-58632
HIGH 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58633
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58634
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58613
HIGH 7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58628
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele… |
|
CVE-2026-58542
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58538
HIGH 7.8
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58540
HIGH 7.8
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58541
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58532
HIGH 7.8
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58537
HIGH 7.8
Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58536
HIGH 7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58527
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-58530
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-57096
HIGH 7.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57091
HIGH 7.8
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56650
HIGH 7.8
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56643
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56644
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56189
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-56182
HIGH 7.8
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56176
HIGH 7.8
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56175
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54125
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-54124
HIGH 7.8
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54115
HIGH 7.8
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50689
HIGH 7.8
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50688
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50677
HIGH 7.8
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50679
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50673
HIGH 7.8
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50676
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50667
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges… |
|
CVE-2026-50655
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50509
HIGH 7.8
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50501
HIGH 7.8
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50499
HIGH 7.8
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50498
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-50493
HIGH 7.8
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50494
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50484
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50486
HIGH 7.8
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50476
HIGH 7.8
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50478
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50471
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50469
HIGH 7.8
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50466
HIGH 7.8
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50462
HIGH 7.8
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50461
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50454
HIGH 7.8
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50457
HIGH 7.8
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50458
HIGH 7.8
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50448
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50450
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized … |
|
CVE-2026-50440
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate p… |
|
CVE-2026-50441
HIGH 7.8
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50433
HIGH 7.8
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50436
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50435
HIGH 7.8
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50427
HIGH 7.8
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50425
HIGH 7.8
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50423
HIGH 7.8
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50422
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50421
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv… |
|
CVE-2026-50412
HIGH 7.8
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50417
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50407
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50405
HIGH 7.8
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50400
HIGH 7.8
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50402
HIGH 7.8
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50399
HIGH 7.8
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50391
HIGH 7.8
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50386
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50388
HIGH 7.8
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50387
HIGH 7.8
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50378
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi… |
|
CVE-2026-50373
HIGH 7.8
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50367
HIGH 7.8
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50363
HIGH 7.8
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50361
HIGH 7.8
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50362
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50357
HIGH 7.8
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-50353
HIGH 7.8
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50347
HIGH 7.8
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50346
HIGH 7.8
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50344
HIGH 7.8
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50337
HIGH 7.8
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50343
HIGH 7.8
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50336
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50332
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50331
HIGH 7.8
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50335
HIGH 7.8
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50329
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50326
HIGH 7.8
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50327
HIGH 7.8
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. |
|
CVE-2026-50321
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv… |
|
CVE-2026-50315
HIGH 7.8
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50317
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to eleva… |
|
CVE-2026-50309
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50313
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-50305
HIGH 7.8
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50306
HIGH 7.8
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58609
HIGH 7.8
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58610
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58635
HIGH 7.8
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privil… |
|
CVE-2026-58601
HIGH 7.8
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58602
HIGH 7.8
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-55004
HIGH 7.8
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54993
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54987
HIGH 7.8
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54991
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-54986
HIGH 7.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54112
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileg… |
|
CVE-2026-54114
HIGH 7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54109
HIGH 7.8
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-50697
HIGH 7.8
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50351
HIGH 7.8
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50311
HIGH 7.8
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50333
HIGH 7.8
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50318
HIGH 7.8
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50308
HIGH 7.8
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49808
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileg… |
|
CVE-2026-50293
HIGH 7.8
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49800
HIGH 7.8
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49793
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-49796
HIGH 7.8
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49797
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2026-49792
HIGH 7.8
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-49783
HIGH 7.8
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-49176
HIGH 7.8
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49175
HIGH 7.8
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49173
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49166
HIGH 7.8
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49170
HIGH 7.8
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42982
HIGH 7.8
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44800
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-58531
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges … |
|
CVE-2026-57089
HIGH 7.5
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56648
HIGH 7.5
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50647
HIGH 7.5
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n… |
|
CVE-2026-50505
HIGH 7.5
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. |
|
CVE-2026-50500
HIGH 7.5
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-50496
HIGH 7.5
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50470
HIGH 7.5
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50463
HIGH 7.5
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50424
HIGH 7.5
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50414
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50411
HIGH 7.5
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50379
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50330
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-54983
HIGH 7.5
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-54119
HIGH 7.5
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50695
HIGH 7.5
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50696
HIGH 7.5
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-49787
HIGH 7.5
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-49788
HIGH 7.5
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-49171
HIGH 7.5
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40378
HIGH 7.5
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over … |
|
CVE-2026-54127
HIGH 7.4
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-50482
HIGH 7.3
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-58640
HIGH 7.3
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-50364
HIGH 7.3
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49789
HIGH 7.3
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49790
HIGH 7.3
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-58529
HIGH 7.1
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. |
|
CVE-2026-50682
HIGH 7.1
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. |
|
CVE-2026-50465
HIGH 7.1
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-50451
HIGH 7.1
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50428
HIGH 7.1
Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-55144
HIGH 7.1
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. |
|
CVE-2026-50354
HIGH 7.1
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49791
HIGH 7.1
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri… |
|
CVE-2026-49165
HIGH 7.1
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. |
|
CVE-2026-58598
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p… |
|
CVE-2026-58629
HIGH 7.0
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58637
HIGH 7.0
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58619
HIGH 7.0
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58544
HIGH 7.0
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57093
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56183
HIGH 7.0
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56187
HIGH 7.0
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56173
HIGH 7.0
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50672
HIGH 7.0
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50674
HIGH 7.0
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50669
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-50503
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50490
HIGH 7.0
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50491
HIGH 7.0
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50459
HIGH 7.0
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-50452
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… |
|
CVE-2026-50449
HIGH 7.0
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50410
HIGH 7.0
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50406
HIGH 7.0
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50404
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege… |
|
CVE-2026-50403
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50392
HIGH 7.0
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50393
HIGH 7.0
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50396
HIGH 7.0
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50397
HIGH 7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50390
HIGH 7.0
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50372
HIGH 7.0
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50371
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege… |
|
CVE-2026-50359
HIGH 7.0
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50358
HIGH 7.0
Use after free in Windows Media allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50348
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi… |
|
CVE-2026-50345
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50322
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-50307
HIGH 7.0
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58526
HIGH 7.0
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54996
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-54989
HIGH 7.0
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54129
HIGH 7.0
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54111
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-50384
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate pr… |
|
CVE-2026-50356
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… |
|
CVE-2026-50323
HIGH 7.0
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50325
HIGH 7.0
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50297
HIGH 7.0
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49806
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-50296
HIGH 7.0
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49802
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-49805
HIGH 7.0
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49803
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to… |
|
CVE-2026-49784
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele… |
|
CVE-2026-49183
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat… |
|
CVE-2026-48572
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p… |
|
CVE-2026-48571
HIGH 7.0
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49162
HIGH 7.0
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58528
MEDIUM 6.8
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-50668
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50492
MEDIUM 6.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-54132
MEDIUM 6.8
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50299
MEDIUM 6.8
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-50298
MEDIUM 6.8
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-49168
MEDIUM 6.8
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-58546
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-58539
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-58533
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-58535
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-57982
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. |
|
CVE-2026-56168
MEDIUM 6.5
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. |
|
CVE-2026-54126
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50504
MEDIUM 6.5
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50497
MEDIUM 6.5
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50445
MEDIUM 6.5
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50376
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-50366
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-57976
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-57979
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-55003
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-49799
MEDIUM 6.5
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-34348
MEDIUM 6.5
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-57097
MEDIUM 6.4
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-55000
MEDIUM 6.4
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-58543
MEDIUM 6.3
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat… |
|
CVE-2026-50375
MEDIUM 6.3
Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50374
MEDIUM 6.3
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-57095
MEDIUM 6.2
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-50420
MEDIUM 6.2
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-50294
MEDIUM 6.2
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-49807
MEDIUM 6.2
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-50661
MEDIUM 6.1
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-50495
MEDIUM 6.1
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-50453
MEDIUM 6.1
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-50383
MEDIUM 6.1
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
|
CVE-2026-49174
MEDIUM 6.1
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-58638
MEDIUM 6.0
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-56649
MEDIUM 5.9
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e… |
|
CVE-2026-58547
MEDIUM 5.5
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-58545
MEDIUM 5.5
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-57083
MEDIUM 5.5
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-57084
MEDIUM 5.5
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-57085
MEDIUM 5.5
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
|
CVE-2026-56184
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-50690
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-50681
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-50483
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-50475
MEDIUM 5.5
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50473
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50455
MEDIUM 5.5
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. |
|
CVE-2026-50456
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50442
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50434
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-50437
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-50430
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-50431
MEDIUM 5.5
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability |
|
CVE-2026-50409
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-50401
MEDIUM 5.5
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-50394
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-50389
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-50377
MEDIUM 5.5
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50352
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-50341
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-50339
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-50334
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. |
|
CVE-2026-49177
MEDIUM 5.5
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. |
|
CVE-2026-58614
MEDIUM 5.5
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-54997
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-50381
MEDIUM 5.5
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local… |
|
CVE-2026-50350
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo… |
|
CVE-2026-50316
MEDIUM 5.5
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50300
MEDIUM 5.5
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50303
MEDIUM 5.5
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-50295
MEDIUM 5.5
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-49801
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-49180
MEDIUM 5.5
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca… |
|
CVE-2026-40422
MEDIUM 5.5
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-41087
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34349
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-34346
MEDIUM 5.5
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. |
|
CVE-2026-33842
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34328
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-50432
MEDIUM 5.3
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. |
|
CVE-2026-50415
MEDIUM 5.3
Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-44806
MEDIUM 5.3
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50418
MEDIUM 5.1
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2026-50310
MEDIUM 4.7
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. |
|
CVE-2026-50312
MEDIUM 4.7
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49167
MEDIUM 4.7
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49794
MEDIUM 4.6
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-50485
MEDIUM 4.5
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
|
CVE-2026-50302
MEDIUM 4.2
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-50419
LOW 3.3
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50416
LOW 3.3
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |
Déployer ce correctif Windows sur votre flotte
Appaloosa pousse les mises à jour Windows et vérifie leur application sur tout votre parc.