Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 53 min 54 sec ago

CVE-2026-45486 Microsoft Word Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45485 Microsoft Office Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-45483 Microsoft Office Project Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2025-10263 ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]

Tue, 06/09/2026 - 14:00
No cwe for this issue in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-33828 Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-34335 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42902 Microsoft PowerToys Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-44817 Microsoft Excel Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-44818 Microsoft Excel Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-44819 Microsoft Office Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-44820 Microsoft Excel Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-44821 Microsoft Office Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-44823 Microsoft Excel Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-44824 Microsoft Office Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45453 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-45456 Microsoft Outlook and Word Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45458 Microsoft Outlook and Word Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45460 Microsoft Office Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

Pages