Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 53 min 38 sec ago

CVE-2026-45461 Microsoft Office Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45466 Microsoft Word Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-45487 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-45490 .NET SDK Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-45491 .NET Tampering Vulnerability

Tue, 06/09/2026 - 14:00
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
Categories: Microsoft

CVE-2026-45500 Microsoft Exchange Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-45501 Microsoft Exchange Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-45502 Microsoft Exchange Server Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-45503 Microsoft Exchange Server Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-45504 Microsoft Exchange Server Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-45583 Microsoft Exchange Server Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-45605 Windows Bluetooth Service Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-45639 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-45640 Windows Bluetooth Port Driver Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-45606 Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
Categories: Microsoft

CVE-2026-45607 Windows Hyper-V Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45641 Windows Hyper-V Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45634 Windows DHCP Client Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-45642 Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
Categories: Microsoft

CVE-2026-45643 Microsoft Word Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft

Pages