Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 45 min 52 sec ago

CVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Tue, 09/08/2026 - 14:00

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-84003 Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability

Tue, 09/08/2026 - 14:00

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Categories: Microsoft

CVE-2026-66303 Skype for Business and Lync Denial of Service Vulnerability

Tue, 09/08/2026 - 14:00

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-66307 Skype for Business and Lync Denial of Service Vulnerability

Tue, 09/08/2026 - 14:00

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-62804 Microsoft Word Remote Code Execution Vulnerability

Tue, 09/08/2026 - 14:00
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft

Chromium: CVE-2026-84359 Information leak in Skia

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84358 Improper privilege management in Downloads

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84357 Improper input validation in Omnibox

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84356 UI misrepresentation in FullScreen

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84355 Incorrect authorization in Navigation

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84354 Incorrect authorization in FileSystem

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84353 Use after free in Shared Tab Groups

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84351 Buffer overflow in GPU

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84350 Use after free in TabStrip

Thu, 09/03/2026 - 23:59
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84349 Use after free in Browser

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84348 Information leak in MediaCapture

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84347 Use after free in WebRTC

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84335 Incorrect authorization in TabStrip

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84334 Incorrect authorization in Chromoting

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Pages