Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 28 min ago

CVE-2026-50445 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-50344 Windows OLE Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50352 Windows Cryptographic Services Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-50382 DirectX Graphics Kernel Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-50436 Windows Kernel Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50437 Windows DWM Core Library Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-50471 Windows NTFS Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-50369 Windows Remote Desktop Services Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-50469 Windows Projected File System Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50454 Windows User Interface Core Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50365 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
Categories: Microsoft

CVE-2026-50426 Windows DNS Server Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
Categories: Microsoft

CVE-2026-50385 Windows Runtime Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50413 Windows Runtime Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50427 Content Delivery Manager Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50421 Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50374 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.
Categories: Microsoft

CVE-2026-50367 Windows Sensor Data Service Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
Categories: Microsoft

Pages