Microsoft security briefs
3328 published alerts for Microsoft products and services.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-40357) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word Information Disclosure vulnerability
Microsoft Word Information Disclosure vulnerability (CVE-2026-35440) was added to Microsoft’s security update guidance. Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-35439) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Admin Center Elevation of Privilege vulnerability
Windows Admin Center Elevation of Privilege vulnerability (CVE-2026-35438) was added to Microsoft’s security update guidance. Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Click-To-Run Elevation of Privilege vulnerability
Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-35436) was added to Microsoft’s security update guidance. Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows 11 Telnet Client Information Disclosure vulnerability
Windows 11 Telnet Client Information Disclosure vulnerability (CVE-2026-35423) was added to Microsoft’s security update guidance. Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Driver Security Feature Bypass vulnerability
Windows TCP/IP Driver Security Feature Bypass vulnerability (CVE-2026-35422) was added to Microsoft’s security update guidance. Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows GDI Remote Code Execution vulnerability
Windows GDI Remote Code Execution vulnerability (CVE-2026-35421) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-35420) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows DWM Core Library Information Disclosure vulnerability
Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-35419) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-35418) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-35417) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-35416) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Storage Spaces Controller Elevation of Privilege vulnerability
Windows Storage Spaces Controller Elevation of Privilege vulnerability (CVE-2026-35415) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-34351) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Storport Miniport Driver Denial of Service vulnerability
Windows Storport Miniport Driver Denial of Service vulnerability (CVE-2026-34350) was added to Microsoft’s security update guidance. Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-34347) was added to Microsoft’s security update guidance. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-34345) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-34344) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Application Identity (AppID) Subsystem Elevation of Privilege vulnerability
Windows Application Identity (AppID) Subsystem Elevation of Privilege vulnerability (CVE-2026-34343) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Print Spooler Elevation of Privilege vulnerability
Windows Print Spooler Elevation of Privilege vulnerability (CVE-2026-34342) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege vulnerability
Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege vulnerability (CVE-2026-34341) was added to Microsoft’s security update guidance. Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Projected File System Elevation of Privilege vulnerability
Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-34340) was added to Microsoft’s security update guidance. Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service vulnerability (CVE-2026-34339) was added to Microsoft’s security update guidance. Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.