Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Volume Manager Extension Driver Elevation of Privilege vulnerability
Windows Volume Manager Extension Driver Elevation of Privilege vulnerability (CVE-2026-77904) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-77901) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Security Center Elevation of Privilege vulnerability
Windows Security Center Elevation of Privilege vulnerability (CVE-2026-77899) was added to Microsoft’s security update guidance. <p>Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-77898) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Power Automate Desktop Elevation of Privilege vulnerability
Microsoft Power Automate Desktop Elevation of Privilege vulnerability (CVE-2026-77897) was added to Microsoft’s security update guidance. <p>Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Denial of Service vulnerability
Windows Remote Desktop Client Denial of Service vulnerability (CVE-2026-77896) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77895) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-77894) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77893) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Boot Manager Elevation of Privilege vulnerability
Windows Boot Manager Elevation of Privilege vulnerability (CVE-2026-77892) was added to Microsoft’s security update guidance. <p>No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-77891) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77890) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77889) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77888) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-77887) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77886) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-77505) was added to Microsoft’s security update guidance. <p>Use after free in DNS Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-77504) was added to Microsoft’s security update guidance. <p>Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-77503) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77502) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77501) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-77500) was added to Microsoft’s security update guidance. <p>Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77499) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-77498) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.