Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 49 min 37 sec ago

CVE-2026-42975 Windows Bluetooth Port Driver Remote Code Execution

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
Categories: Microsoft

CVE-2026-47300 ASP.NET Core Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-47302 .NET Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-47303 ASP.NET Core Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-42990 SQL Server ODBC driver Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-48572 Windows App Package Installer Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-48571 Windows App Package Installer Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-49165 Microsoft Windows App Store Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-49166 Windows Print Configuration Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
Categories: Microsoft

CVE-2026-49169 Windows DNS Server Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in DNS Server allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-49170 Windows StateRepository API Server file Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49171 Windows Speech Runtime Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49176 Windows WalletService Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49175 Windows DNS Client Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-49172 Windows FTP Service Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-49173 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

Pages