Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-40357

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-40357) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35440

Microsoft Word Information Disclosure vulnerability

Microsoft Word Information Disclosure vulnerability (CVE-2026-35440) was added to Microsoft’s security update guidance. Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35439

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-35439) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35438

Windows Admin Center Elevation of Privilege vulnerability

Windows Admin Center Elevation of Privilege vulnerability (CVE-2026-35438) was added to Microsoft’s security update guidance. Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35436

Microsoft Office Click-To-Run Elevation of Privilege vulnerability

Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-35436) was added to Microsoft’s security update guidance. Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35423

Windows 11 Telnet Client Information Disclosure vulnerability

Windows 11 Telnet Client Information Disclosure vulnerability (CVE-2026-35423) was added to Microsoft’s security update guidance. Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35422

Windows TCP/IP Driver Security Feature Bypass vulnerability

Windows TCP/IP Driver Security Feature Bypass vulnerability (CVE-2026-35422) was added to Microsoft’s security update guidance. Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35421

Windows GDI Remote Code Execution vulnerability

Windows GDI Remote Code Execution vulnerability (CVE-2026-35421) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35420

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-35420) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35419

Windows DWM Core Library Information Disclosure vulnerability

Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-35419) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35418

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-35418) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35417

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-35417) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35416

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-35416) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35415

Windows Storage Spaces Controller Elevation of Privilege vulnerability

Windows Storage Spaces Controller Elevation of Privilege vulnerability (CVE-2026-35415) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34351

Windows TCP/IP Elevation of Privilege vulnerability

Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-34351) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34350

Windows Storport Miniport Driver Denial of Service vulnerability

Windows Storport Miniport Driver Denial of Service vulnerability (CVE-2026-34350) was added to Microsoft’s security update guidance. Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34347

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-34347) was added to Microsoft’s security update guidance. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34345

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-34345) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34344

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-34344) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34343

Windows Application Identity (AppID) Subsystem Elevation of Privilege vulnerability

Windows Application Identity (AppID) Subsystem Elevation of Privilege vulnerability (CVE-2026-34343) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34342

Windows Print Spooler Elevation of Privilege vulnerability

Windows Print Spooler Elevation of Privilege vulnerability (CVE-2026-34342) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34341

Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege vulnerability

Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege vulnerability (CVE-2026-34341) was added to Microsoft’s security update guidance. Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34340

Windows Projected File System Elevation of Privilege vulnerability

Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-34340) was added to Microsoft’s security update guidance. Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34339

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service vulnerability (CVE-2026-34339) was added to Microsoft’s security update guidance. Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.