Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Core Messaging Elevation of Privilege vulnerability
Windows Core Messaging Elevation of Privilege vulnerability (CVE-2026-70584) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Core Messaging Elevation of Privilege vulnerability
Windows Core Messaging Elevation of Privilege vulnerability (CVE-2026-70583) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Management Instrumentation Elevation of Privilege vulnerability
Windows Management Instrumentation Elevation of Privilege vulnerability (CVE-2026-70582) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-70581) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Mobile Broadband Information Disclosure vulnerability
Windows Mobile Broadband Information Disclosure vulnerability (CVE-2026-70579) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Credential Guard Elevation of Privilege vulnerability
Windows Credential Guard Elevation of Privilege vulnerability (CVE-2026-70578) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Modern Device Management (MDM) Elevation of Privilege vulnerability
Windows Modern Device Management (MDM) Elevation of Privilege vulnerability (CVE-2026-70577) was added to Microsoft’s security update guidance. <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Schannel Denial of Service vulnerability
Windows Schannel Denial of Service vulnerability (CVE-2026-70575) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-70573) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-70572) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-70570) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Elevation of Privilege vulnerability
Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-70569) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Defender Firewall Service Elevation of Privilege vulnerability
Windows Defender Firewall Service Elevation of Privilege vulnerability (CVE-2026-70568) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Display Enhancement Service Elevation of Privilege vulnerability
Windows Display Enhancement Service Elevation of Privilege vulnerability (CVE-2026-70567) was added to Microsoft’s security update guidance. <p>Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows AF_UNIX Socket Provider Elevation of Privilege vulnerability
Windows AF_UNIX Socket Provider Elevation of Privilege vulnerability (CVE-2026-70565) was added to Microsoft’s security update guidance. <p>Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Elevation of Privilege vulnerability
Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-70564) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Shell Spoofing vulnerability
Windows Shell Spoofing vulnerability (CVE-2026-70563) was added to Microsoft’s security update guidance. <p>Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Audio Service Elevation of Privilege vulnerability
Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-70562) was added to Microsoft’s security update guidance. <p>Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Azure AI Language Elevation of Privilege vulnerability
Azure AI Language Elevation of Privilege vulnerability (CVE-2026-70352) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft WebP Image Extension Remote Code Execution vulnerability
Microsoft WebP Image Extension Remote Code Execution vulnerability (CVE-2026-70351) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-70342) was added to Microsoft’s security update guidance. <p>Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-70334) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Remote Code Execution vulnerability
Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-70296) was added to Microsoft’s security update guidance. <p>Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-70289) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.