Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 30 min 19 sec ago

CVE-2026-42904 Windows TCP/IP Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
Categories: Microsoft

CVE-2026-42905 Windows DWM Core Library Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-42906 Windows Shell Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42907 Windows Shell Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42908 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-42980 NT OS Kernel Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42909 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-42916 NT OS Kernel Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42911 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42913 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42914 Windows Kerberos Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Information published.
Categories: Microsoft

CVE-2026-42915 Windows TCP/IP Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network.
Categories: Microsoft

CVE-2026-42968 Windows Telephony Server Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42972 Windows Hyper-V Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42969 Windows Push Notification Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42971 Windows Push Notification Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42970 Windows Push Notification Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42973 Windows Push Notification Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42984 Windows Kernel Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

Pages