Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-42825

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-42825) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42898

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-42898) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41088

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-41088) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-26168

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-26168) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-24293

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-24293) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45584

Microsoft Defender Remote Code Execution vulnerability

Microsoft Defender Remote Code Execution vulnerability (CVE-2026-45584) was added to Microsoft’s security update guidance. In the Security Updates table, added links to the Release Notes. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34336

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-34336) was added to Microsoft’s security update guidance. The security impact for this CVE has been revised based on a re-assessment of the vulnerability. The original classification of Information Disclosure (ID) has been updated to Elevation of Privilege (EoP). If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33117

Azure SDK for Java Security Feature Bypass vulnerability

Azure SDK for Java Security Feature Bypass vulnerability (CVE-2026-33117) was added to Microsoft’s security update guidance. The executive summary has been updated to include additional details about this vulnerability. This change does not affect the available security updates. Customers should install the recommended updates to remain protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-45498

Microsoft Defender Denial of Service Vulnerability

Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45498). Microsoft Defender contains an unspecified vulnerability that allows for denial of service. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-41091

Microsoft Defender Link Following Vulnerability

Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-41091). Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40367

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-40367) was added to Microsoft’s security update guidance. Today's changes were made in error and have been reverted. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2010-0806

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0806). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2010-0249

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0249). Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2009-1537

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-1537). Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2008-4250

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4250). Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. CISA remediation due date: 2026-06-03. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42822

Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability

Azure Local Disconnected Operations (ALDO) Elevation of Privilege vulnerability (CVE-2026-42822) was added to Microsoft’s security update guidance. Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32185

Microsoft Teams Spoofing vulnerability

Microsoft Teams Spoofing vulnerability (CVE-2026-32185) was added to Microsoft’s security update guidance. The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40379

Azure Entra ID Spoofing vulnerability

Azure Entra ID Spoofing vulnerability (CVE-2026-40379) was added to Microsoft’s security update guidance. Corrected CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32170

Windows Rich Text Edit Elevation of Privilege vulnerability

Windows Rich Text Edit Elevation of Privilege vulnerability (CVE-2026-32170) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32161

Windows Native WiFi Miniport Driver Remote Code Execution vulnerability

Windows Native WiFi Miniport Driver Remote Code Execution vulnerability (CVE-2026-32161) was added to Microsoft’s security update guidance. Updated Hotpatch links. This is in informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41615

Microsoft Authenticator Information Disclosure vulnerability

Microsoft Authenticator Information Disclosure vulnerability (CVE-2026-41615) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42833

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-42833) was added to Microsoft’s security update guidance. Updated the fixed version number. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42896

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-42896) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42893

Microsoft Outlook for iOS Tampering vulnerability

Microsoft Outlook for iOS Tampering vulnerability (CVE-2026-42893) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.