Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Deployment Services Remote Code Execution vulnerability
Windows Deployment Services Remote Code Execution vulnerability (CVE-2026-72954) was added to Microsoft’s security update guidance. <p>Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Driver Elevation of Privilege vulnerability
Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-72953) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Remote Code Execution vulnerability
Windows Spaceport.sys Remote Code Execution vulnerability (CVE-2026-72952) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-72950) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.
Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service vulnerability
Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service vulnerability (CVE-2026-72949) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-72948) was added to Microsoft’s security update guidance. <p>Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows File History Service Elevation of Privilege vulnerability
Windows File History Service Elevation of Privilege vulnerability (CVE-2026-72947) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Storage Port Driver Elevation of Privilege vulnerability
Microsoft Storage Port Driver Elevation of Privilege vulnerability (CVE-2026-72946) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Task Scheduler Information Disclosure vulnerability
Windows Task Scheduler Information Disclosure vulnerability (CVE-2026-72945) was added to Microsoft’s security update guidance. <p>Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Deployment Services Remote Code Execution vulnerability
Windows Deployment Services Remote Code Execution vulnerability (CVE-2026-72943) was added to Microsoft’s security update guidance. <p>Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Information Disclosure vulnerability
Windows Spaceport.sys Information Disclosure vulnerability (CVE-2026-72942) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-72941) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Schannel Remote Code Execution vulnerability
Windows Schannel Remote Code Execution vulnerability (CVE-2026-72940) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Denial of Service vulnerability
Windows Routing and Remote Access Service (RRAS) Denial of Service vulnerability (CVE-2026-72939) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Information Disclosure vulnerability
Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72938) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Storage Port Driver Information Disclosure vulnerability
Windows Storage Port Driver Information Disclosure vulnerability (CVE-2026-72937) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows SMB Client Remote Code Execution vulnerability
Windows SMB Client Remote Code Execution vulnerability (CVE-2026-72936) was added to Microsoft’s security update guidance. <p>Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-72935) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft WDAC OLE DB provider for SQL Remote Code Execution vulnerability
Microsoft WDAC OLE DB provider for SQL Remote Code Execution vulnerability (CVE-2026-72933) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Message Queuing Queue Manager Information Disclosure vulnerability
Windows Message Queuing Queue Manager Information Disclosure vulnerability (CVE-2026-72932) was added to Microsoft’s security update guidance. <p>Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service vulnerability (CVE-2026-72931) was added to Microsoft’s security update guidance. <p>Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution vulnerability (CVE-2026-72930) was added to Microsoft’s security update guidance. <p>Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-72929) was added to Microsoft’s security update guidance. <p>Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-72928) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.