Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 20 min 33 sec ago

CVE-2026-72927 Winsock Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-72928 Windows DNS Server Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-72931 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability

Tue, 09/08/2026 - 14:00

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

Categories: Microsoft

CVE-2026-72936 Windows SMB Client Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-72933 Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-72932 Windows Message Queuing Queue Manager Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00

Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-72952 Windows Spaceport.sys Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

Categories: Microsoft

CVE-2026-72953 Windows USB Driver Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-72941 Windows Biometric Service Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-72942 Windows Spaceport.sys Information Disclosure Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-72957 Windows Deployment Services Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.

Categories: Microsoft

CVE-2026-72950 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Categories: Microsoft

CVE-2026-72959 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Categories: Microsoft

CVE-2026-72954 Windows Deployment Services Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-72960 Windows Media Player Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-72961 Windows Hyper-V Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-72964 Windows Internet Connection Sharing (ICS) Tampering Vulnerability

Tue, 09/08/2026 - 14:00

Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.

Categories: Microsoft

CVE-2026-72966 Windows Remote Access Connection Manager Tampering Vulnerability

Tue, 09/08/2026 - 14:00

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

Categories: Microsoft

CVE-2026-72967 Windows Network Connection Broker Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-68896 Microsoft Windows Search Component Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

Pages