Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 53 min 34 sec ago

CVE-2026-49173 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49174 DNS Client Tampering Vulnerability

Tue, 07/14/2026 - 14:00
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
Categories: Microsoft

CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-49784 Microsoft Windows App Store Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50506 OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability

Tue, 07/14/2026 - 14:00
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-50663 Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-54983 Windows Active Directory Federation Services Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-54129 Windows Hyper-V Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-54989 Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-54987 Windows Overlay Filter Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-54990 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Categories: Microsoft

CVE-2026-54111 Universal Print Management Service Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-54991 Windows USB Print Driver Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-54132 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
Categories: Microsoft

Pages