Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 7 min 40 sec ago

CVE-2026-70345 Windows Installer Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-70346 Windows Installer Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-70347 Windows Installer Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-70348 Windows Management Services Denial of Service Vulnerability

Tue, 08/11/2026 - 14:00
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Categories: Microsoft

CVE-2026-70355 Microsoft SharePoint Server Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

Tue, 08/11/2026 - 14:00
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Categories: Microsoft

CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability

Tue, 08/11/2026 - 14:00
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-58641 .NET Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-59122 Windows Telephony Service Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

Tue, 08/11/2026 - 14:00
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-59131 AMD Zen Information Disclosure Vulnerability

Tue, 08/11/2026 - 14:00
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-61349 Windows Work Folder Service Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

Pages