Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-42983

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42983) was added to Microsoft’s security update guidance. Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42981

Windows Performance Monitor Remote Code Execution vulnerability

Windows Performance Monitor Remote Code Execution vulnerability (CVE-2026-42981) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42979

Windows Push Notifications Elevation of Privilege vulnerability

Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-42979) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42978

Windows Push Notifications Elevation of Privilege vulnerability

Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-42978) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42977

Windows Push Notifications Elevation of Privilege vulnerability

Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-42977) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42974

Windows Performance Monitor Remote Code Execution vulnerability

Windows Performance Monitor Remote Code Execution vulnerability (CVE-2026-42974) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42973

Windows Push Notification Information Disclosure vulnerability

Windows Push Notification Information Disclosure vulnerability (CVE-2026-42973) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42972

Windows Hyper-V Information Disclosure vulnerability

Windows Hyper-V Information Disclosure vulnerability (CVE-2026-42972) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42971

Windows Push Notification Information Disclosure vulnerability

Windows Push Notification Information Disclosure vulnerability (CVE-2026-42971) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42970

Windows Push Notification Information Disclosure vulnerability

Windows Push Notification Information Disclosure vulnerability (CVE-2026-42970) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42969

Windows Push Notification Information Disclosure vulnerability

Windows Push Notification Information Disclosure vulnerability (CVE-2026-42969) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42968

Windows Telephony Server Information Disclosure vulnerability

Windows Telephony Server Information Disclosure vulnerability (CVE-2026-42968) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42911

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-42911) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42908

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-42908) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42907

Windows Shell Information Disclosure vulnerability

Windows Shell Information Disclosure vulnerability (CVE-2026-42907) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42906

Windows Shell Information Disclosure vulnerability

Windows Shell Information Disclosure vulnerability (CVE-2026-42906) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42905

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42905) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42904

Windows TCP/IP Elevation of Privilege vulnerability

Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-42904) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42902

Microsoft PowerToys Elevation of Privilege vulnerability

Microsoft PowerToys Elevation of Privilege vulnerability (CVE-2026-42902) was added to Microsoft’s security update guidance. Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42837

Windows Projected File System Elevation of Privilege vulnerability

Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-42837) was added to Microsoft’s security update guidance. Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42836

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege vulnerability

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege vulnerability (CVE-2026-42836) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42835

Microsoft Teams for Android Information Disclosure vulnerability

Microsoft Teams for Android Information Disclosure vulnerability (CVE-2026-42835) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42829

Windows Administrator Protection Secure Feature Bypass vulnerability

Windows Administrator Protection Secure Feature Bypass vulnerability (CVE-2026-42829) was added to Microsoft’s security update guidance. Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41108

Windows DNS Client Elevation of Privilege vulnerability

Windows DNS Client Elevation of Privilege vulnerability (CVE-2026-41108) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.