Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 37 min 44 sec ago

CVE-2026-49808 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50293 Windows Internal Task Bar Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50316 Windows Kernel Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-50354 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50296 DirectX Graphics Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50297 Win32k Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50325 Win32k Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50356 Microsoft Windows App Store Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50384 Windows Clip Service Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50295 Windows Zero Trust DNS Security Feature Bypass Vulnerability

Tue, 07/14/2026 - 14:00
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-50350 Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-50381 Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-50300 Windows DWM Core Library Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-50303 Windows Key Guard Security Feature Bypass Vulnerability

Tue, 07/14/2026 - 14:00
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-50364 Windows Backup Service Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50302 Windows Cryptographic Services Security Feature Bypass Vulnerability

Tue, 07/14/2026 - 14:00
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
Categories: Microsoft

CVE-2026-50332 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50372 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50305 Microsoft Brokering File System Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50329 Microsoft DWM Core Library Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

Pages