Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 27 min 1 sec ago

CVE-2026-49160 HTTP.sys Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-50507 Windows BitLocker Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Categories: Microsoft

CVE-2026-50511 Microsoft PC Manager Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-50512 Microsoft PC Manager Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42836 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42837 Windows Projected File System Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42903 Windows Kerberos Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Information published.
Categories: Microsoft

CVE-2026-42904 Windows TCP/IP Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
Categories: Microsoft

CVE-2026-42905 Windows DWM Core Library Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-42906 Windows Shell Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42907 Windows Shell Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42908 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-42980 NT OS Kernel Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42909 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-42916 NT OS Kernel Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42911 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42913 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42914 Windows Kerberos Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Information published.
Categories: Microsoft

CVE-2026-42915 Windows TCP/IP Denial of Service Vulnerability

Tue, 06/09/2026 - 14:00
Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network.
Categories: Microsoft

Pages