Windows · Build corrective
10.0.17763.9121
Advisory MSRCLa build Windows 10.0.17763.9121, publiée le 2026-08-11, corrige 183 CVE, dont 1 activement exploitée (CISA KEV), déployée sur 3 SKU.
- Publiée le
- 2026-08-11
- SKU couvertes
- 3
- CVE corrigées
- 183
- KEV CISA
- 1
3 critique · 125 élevé
SKU Windows couvertes par cette build
Les SKU ci-dessous partagent ce numéro de build MSRC. Pousser la KB correspondante les sécurise toutes simultanément.
CVE corrigées par cette build
| CVE | Sévérité | KEV | Publié | Description |
|---|---|---|---|---|
|
CVE-2026-68820
KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | KEV | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65791
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a netwo… |
CRITICAL 9.8 | — | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62878
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. |
CRITICAL 9.8 | — | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62823
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netw… |
HIGH 8.8 | — | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-62822
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
HIGH 8.8 | — | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62816
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute c… |
HIGH 8.8 | — | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-62817
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. |
HIGH 8.8 | — | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | |
|
CVE-2026-62818
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a ne… |
HIGH 8.8 | — | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | |
|
CVE-2026-62800
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | |
|
CVE-2026-62795
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code … |
HIGH 8.8 | — | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62785
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to e… |
HIGH 8.8 | — | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62790
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. |
HIGH 8.8 | — | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | |
|
CVE-2026-62784
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execu… |
HIGH 8.8 | — | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. | |
|
CVE-2026-49179
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows … |
HIGH 8.8 | — | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code… | |
|
CVE-2026-71331
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an u… |
HIGH 8.1 | — | Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code ove… | |
|
CVE-2026-66802
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestat… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestatio… | |
|
CVE-2026-65796
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a netwo… |
HIGH 8.1 | — | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-65789
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
HIGH 8.1 | — | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-65679
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a netwo… |
HIGH 8.1 | — | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62889
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a n… |
HIGH 8.1 | — | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62820
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an un… |
HIGH 8.1 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over… | |
|
CVE-2026-62819
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized acces… |
HIGH 8.1 | — | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | |
|
CVE-2026-62792
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. |
HIGH 8.1 | — | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62781
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. |
HIGH 8.1 | — | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-62778
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. |
HIGH 8.1 | — | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | |
|
CVE-2026-6726
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker w… |
HIGH 7.9 | — | An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a cred… | |
|
CVE-2026-70346
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-70347
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-70344
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-70345
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-66799
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65814
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65786
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65787
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65790
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65773
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65774
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65775
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65671
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62894
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62890
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. | |
|
CVE-2026-62885
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62876
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62877
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62880
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62812
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to … |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62803
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to … |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62807
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to … |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62797
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62783
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privile… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62777
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privil… |
HIGH 7.8 | — | Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62776
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to … |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62771
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privilege… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62768
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62770
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62754
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62755
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62758
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privile… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62761
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to … |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62752
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62747
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62741
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62735
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62739
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62733
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62732
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62719
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62717
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62721
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate p… |
HIGH 7.8 | — | Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62713
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privilege… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62712
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62711
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62707
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62710
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges lo… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62696
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker… |
HIGH 7.8 | — | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62698
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62700
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62701
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62692
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges local… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61937
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61932
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker… |
HIGH 7.8 | — | Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61925
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61930
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61926
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61923
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges l… |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61367
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevat… |
HIGH 7.8 | — | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61364
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevat… |
HIGH 7.8 | — | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61365
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevat… |
HIGH 7.8 | — | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61356
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevat… |
HIGH 7.8 | — | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) a… |
HIGH 7.8 | — | Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate … | |
|
CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61349
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-59127
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-56174
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. |
HIGH 7.8 | — | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-54984
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. |
HIGH 7.8 | — | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. | |
|
CVE-2026-42976
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loc… |
HIGH 7.8 | — | Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65681
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. |
HIGH 7.5 | — | Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-62787
Use after free in Windows DNS allows an authorized attacker to execute code over a network. |
HIGH 7.5 | — | Use after free in Windows DNS allows an authorized attacker to execute code over a network. | |
|
CVE-2026-61363
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-61352
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client al… |
HIGH 7.5 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… | |
|
CVE-2026-59132
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. |
HIGH 7.5 | — | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-59134
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
HIGH 7.5 | — | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
|
CVE-2026-54113
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service … |
HIGH 7.5 | — | Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-70307
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65678
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62908
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine al… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p… | |
|
CVE-2026-62892
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62773
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62774
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62748
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-62753
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62729
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-62734
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-62723
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62724
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62725
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62726
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62728
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacke… |
HIGH 7.0 | — | Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61939
Use after free in Winlogon allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62690
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notificatio… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… | |
|
CVE-2026-61366
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61348
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc… |
HIGH 7.0 | — | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61346
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-59122
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Servic… |
HIGH 7.0 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… | |
|
CVE-2026-59125
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-50472
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. |
HIGH 7.0 | — | Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62727
Windows Telephony Service Elevation of Privilege Vulnerability |
HIGH 7.0 | — | Windows Telephony Service Elevation of Privilege Vulnerability | |
|
CVE-2026-62699
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker t… |
MEDIUM 6.8 | — | Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. | |
|
CVE-2026-70330
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-70304
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65799
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65795
No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65797
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-65798
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62881
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62883
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-62769
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
MEDIUM 6.7 | — | Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | |
|
CVE-2026-61920
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an au… |
MEDIUM 6.6 | — | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a… | |
|
CVE-2026-65794
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-62814
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62782
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-62750
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an a… |
MEDIUM 6.5 | — | Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. | |
|
CVE-2026-62742
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62745
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62718
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62720
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62715
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62716
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-62714
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information o… |
MEDIUM 6.5 | — | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | |
|
CVE-2026-61924
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-61921
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-61918
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
MEDIUM 6.5 | — | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
|
CVE-2026-59138
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netw… |
MEDIUM 6.5 | — | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | |
|
CVE-2026-61345
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netw… |
MEDIUM 6.5 | — | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | |
|
CVE-2026-68819
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. |
MEDIUM 5.9 | — | Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. | |
|
CVE-2026-6727
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with … |
MEDIUM 5.9 | — | A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may … | |
|
CVE-2026-59130
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
MEDIUM 5.6 | — | No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | |
|
CVE-2026-59131
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
MEDIUM 5.6 | — | No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | |
|
CVE-2026-65784
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | |
|
CVE-2026-65662
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62887
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62796
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62793
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62786
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62746
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62743
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62740
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locall… |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62738
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62730
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62703
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62709
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | |
|
CVE-2026-61936
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature l… |
MEDIUM 5.5 | — | Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | |
|
CVE-2026-61928
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
MEDIUM 5.5 | — | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | |
|
CVE-2026-61360
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. | |
|
CVE-2026-61347
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-59136
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locall… |
MEDIUM 5.5 | — | Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | |
|
CVE-2026-59137
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information lo… |
MEDIUM 5.5 | — | Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. | |
|
CVE-2026-59135
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
MEDIUM 5.5 | — | Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | |
|
CVE-2026-59128
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locall… |
MEDIUM 5.5 | — | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | |
|
CVE-2026-62757
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securi… |
MEDIUM 5.3 | — | Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. | |
|
CVE-2026-61368
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. |
MEDIUM 5.0 | — | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. | |
|
CVE-2026-61350
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |
MEDIUM 4.6 | — | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |