Microsoft security briefs
3328 published alerts for Microsoft products and services.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42983) was added to Microsoft’s security update guidance. Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Performance Monitor Remote Code Execution vulnerability
Windows Performance Monitor Remote Code Execution vulnerability (CVE-2026-42981) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Push Notifications Elevation of Privilege vulnerability
Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-42979) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Push Notifications Elevation of Privilege vulnerability
Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-42978) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Push Notifications Elevation of Privilege vulnerability
Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-42977) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Performance Monitor Remote Code Execution vulnerability
Windows Performance Monitor Remote Code Execution vulnerability (CVE-2026-42974) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Push Notification Information Disclosure vulnerability
Windows Push Notification Information Disclosure vulnerability (CVE-2026-42973) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Information Disclosure vulnerability
Windows Hyper-V Information Disclosure vulnerability (CVE-2026-42972) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Push Notification Information Disclosure vulnerability
Windows Push Notification Information Disclosure vulnerability (CVE-2026-42971) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Push Notification Information Disclosure vulnerability
Windows Push Notification Information Disclosure vulnerability (CVE-2026-42970) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Push Notification Information Disclosure vulnerability
Windows Push Notification Information Disclosure vulnerability (CVE-2026-42969) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Telephony Server Information Disclosure vulnerability
Windows Telephony Server Information Disclosure vulnerability (CVE-2026-42968) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-42911) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-42908) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Shell Information Disclosure vulnerability
Windows Shell Information Disclosure vulnerability (CVE-2026-42907) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Shell Information Disclosure vulnerability
Windows Shell Information Disclosure vulnerability (CVE-2026-42906) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42905) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-42904) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Microsoft PowerToys Elevation of Privilege vulnerability
Microsoft PowerToys Elevation of Privilege vulnerability (CVE-2026-42902) was added to Microsoft’s security update guidance. Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Projected File System Elevation of Privilege vulnerability
Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-42837) was added to Microsoft’s security update guidance. Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege vulnerability
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege vulnerability (CVE-2026-42836) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams for Android Information Disclosure vulnerability
Microsoft Teams for Android Information Disclosure vulnerability (CVE-2026-42835) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Administrator Protection Secure Feature Bypass vulnerability
Windows Administrator Protection Secure Feature Bypass vulnerability (CVE-2026-42829) was added to Microsoft’s security update guidance. Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Client Elevation of Privilege vulnerability
Windows DNS Client Elevation of Privilege vulnerability (CVE-2026-41108) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.