Microsoft security briefs
3328 published alerts for Microsoft products and services.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-42825) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-42898) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-41088) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-26168) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-24293) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Remote Code Execution vulnerability
Microsoft Defender Remote Code Execution vulnerability (CVE-2026-45584) was added to Microsoft’s security update guidance. In the Security Updates table, added links to the Release Notes. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-34336) was added to Microsoft’s security update guidance. The security impact for this CVE has been revised based on a re-assessment of the vulnerability. The original classification of Information Disclosure (ID) has been updated to Elevation of Privilege (EoP). If you need help checking exposure, call (864) 335-9223.
Azure SDK for Java Security Feature Bypass vulnerability
Azure SDK for Java Security Feature Bypass vulnerability (CVE-2026-33117) was added to Microsoft’s security update guidance. The executive summary has been updated to include additional details about this vulnerability. This change does not affect the available security updates. Customers should install the recommended updates to remain protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Denial of Service Vulnerability
Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45498). Microsoft Defender contains an unspecified vulnerability that allows for denial of service. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Link Following Vulnerability
Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-41091). Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-40367) was added to Microsoft’s security update guidance. Today's changes were made in error and have been reverted. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0806). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0249). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft DirectX NULL Byte Overwrite Vulnerability
Microsoft DirectX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-1537). Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4250). Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.
Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability
Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability (CVE-2026-42822) was added to Microsoft’s security update guidance. Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams Spoofing vulnerability
Microsoft Teams Spoofing vulnerability (CVE-2026-32185) was added to Microsoft’s security update guidance. The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available. If you need help checking exposure, call (864) 335-9223.
Azure Entra ID Spoofing vulnerability
Azure Entra ID Spoofing vulnerability (CVE-2026-40379) was added to Microsoft’s security update guidance. Corrected CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Rich Text Edit Elevation of Privilege vulnerability
Windows Rich Text Edit Elevation of Privilege vulnerability (CVE-2026-32170) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Native WiFi Miniport Driver Remote Code Execution vulnerability
Windows Native WiFi Miniport Driver Remote Code Execution vulnerability (CVE-2026-32161) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Authenticator Information Disclosure vulnerability
Microsoft Authenticator Information Disclosure vulnerability (CVE-2026-41615) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-42833) was added to Microsoft’s security update guidance. Updated the fixed version number. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42896) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Outlook for iOS Tampering vulnerability
Microsoft Outlook for iOS Tampering vulnerability (CVE-2026-42893) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.