Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 54 min 14 sec ago

CVE-2026-69289 Windows Setup Files Cleanup Elevation of Privilege Vulnerability

9 hours 48 min ago

Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69294 Microsoft COM for Windows Information Disclosure Vulnerability

9 hours 48 min ago

Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

Categories: Microsoft

CVE-2026-69314 Windows Device Association Broker Service Elevation of Privilege Vulnerability

9 hours 48 min ago

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69300 Windows Push Notifications Elevation of Privilege Vulnerability

9 hours 48 min ago

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69321 Windows Power Dependency Coordinator Tampering Vulnerability

9 hours 48 min ago

Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.

Categories: Microsoft

CVE-2026-69301 Windows Win32k Elevation of Privilege Vulnerability

9 hours 48 min ago

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69303 Push Message Routing Service Information Disclosure Vulnerability

9 hours 48 min ago
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-69313 Microsoft Standard XPS Elevation of Privilege Vulnerability

9 hours 48 min ago
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-69315 Windows License Manager Information Disclosure Vulnerability

9 hours 48 min ago

Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.

Categories: Microsoft

CVE-2026-69312 Windows NTFS Elevation of Privilege Vulnerability

9 hours 48 min ago

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69308 Microsoft Standard XPS Information Disclosure Vulnerability

9 hours 48 min ago
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-69318 Windows Imaging Component Information Disclosure Vulnerability

9 hours 48 min ago
Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-69317 Windows Remote Desktop Client Information Disclosure Vulnerability

9 hours 48 min ago
Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-69316 Windows Overlay Filter Information Disclosure Vulnerability

9 hours 48 min ago
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-69319 Windows USB Video Driver Elevation of Privilege Vulnerability

9 hours 48 min ago
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-69322 Microsoft Windows Search Component Elevation of Privilege Vulnerability

9 hours 48 min ago

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69324 Windows Performance Monitor Elevation of Privilege Vulnerability

9 hours 48 min ago

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69351 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability

9 hours 48 min ago
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-69329 BranchCache Denial of Service Vulnerability

9 hours 48 min ago
Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-69328 Windows Storage Elevation of Privilege Vulnerability

9 hours 48 min ago

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

Pages