Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 28 min 40 sec ago

CVE-2026-67370 Microsoft SQL Server Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-67373 Microsoft SQL Server Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-67629 Microsoft SQL Server Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-67630 Microsoft SQL Server Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-67631 Microsoft SQL Server Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-67633 Microsoft SQL Server Denial of Service Vulnerability

Tue, 09/08/2026 - 14:00
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-68781 Microsoft SQL Server Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-68784 Microsoft SQL Server Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-68785 Microsoft SQL Server Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-68787 Microsoft SQL Server Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Categories: Microsoft

CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-68830 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-68832 Windows NTFS Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-68833 Windows NTFS Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

Categories: Microsoft

CVE-2026-68835 Windows Print Spooler Components Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-68841 Windows NTFS Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-68847 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-68849 Windows Bluetooth Port Driver Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-68845 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-68846 Windows Kernel Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

Pages