Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 59 min 13 sec ago

CVE-2026-70563 Windows Shell Spoofing Vulnerability

8 hours 53 min ago

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Categories: Microsoft

CVE-2026-70564 Windows Print Spooler Components Elevation of Privilege Vulnerability

8 hours 53 min ago

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-70582 Windows Management Instrumentation Elevation of Privilege Vulnerability

8 hours 53 min ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-70584 Windows Core Messaging Elevation of Privilege Vulnerability

8 hours 53 min ago

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-70585 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

8 hours 53 min ago

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

Categories: Microsoft

CVE-2026-70586 Windows Paint Remote Code Execution Vulnerability

8 hours 53 min ago

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-70587 Windows Remote Desktop Protocol Information Disclosure Vulnerability

8 hours 53 min ago

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-71329 Windows NTFS Remote Code Execution Vulnerability

8 hours 53 min ago
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
Categories: Microsoft

CVE-2026-71336 Windows Work Folder Service Remote Code Execution Vulnerability

8 hours 53 min ago

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-71330 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

8 hours 53 min ago

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-71333 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

8 hours 53 min ago

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71337 Windows Storage Management Provider Elevation of Privilege Vulnerability

8 hours 53 min ago

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71332 Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability

8 hours 53 min ago

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71334 Windows NFS Portmapper Elevation of Privilege Vulnerability

8 hours 53 min ago

Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71338 Windows Failover Cluster Elevation of Privilege Vulnerability

8 hours 53 min ago

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71340 Windows File History Service Elevation of Privilege Vulnerability

8 hours 53 min ago

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71339 Windows Installer Elevation of Privilege Vulnerability

8 hours 53 min ago

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-71350 Windows Spaceport.sys Remote Code Execution Vulnerability

8 hours 53 min ago

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Categories: Microsoft

CVE-2026-71348 Windows Spaceport.sys Remote Code Execution Vulnerability

8 hours 53 min ago

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

Categories: Microsoft

CVE-2026-72926 Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability

8 hours 53 min ago

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

Pages