Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Deployment Services Remote Code Execution vulnerability
Windows Deployment Services Remote Code Execution vulnerability (CVE-2026-69607) was added to Microsoft’s security update guidance. <p>Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Shell Elevation of Privilege vulnerability
Windows Shell Elevation of Privilege vulnerability (CVE-2026-69606) was added to Microsoft’s security update guidance. <p>Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Install Service Elevation of Privilege vulnerability
Microsoft Install Service Elevation of Privilege vulnerability (CVE-2026-69605) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Audio Service Elevation of Privilege vulnerability
Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69604) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Remote Code Execution vulnerability
Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-69603) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows PrintWorkflowUserSvc Elevation of Privilege vulnerability
Windows PrintWorkflowUserSvc Elevation of Privilege vulnerability (CVE-2026-69602) was added to Microsoft’s security update guidance. <p>Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Media Foundation Remote Code Execution vulnerability
Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-69601) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Elevation of Privilege vulnerability
Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69600) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Remote Code Execution vulnerability
Windows iSCSI Remote Code Execution vulnerability (CVE-2026-69598) was added to Microsoft’s security update guidance. <p>Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows HTTP.sys Elevation of Privilege vulnerability
Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-69597) was added to Microsoft’s security update guidance. <p>Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability (CVE-2026-69595) was added to Microsoft’s security update guidance. <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability
Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability (CVE-2026-69594) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69593) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability (CVE-2026-69592) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-69591) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-69590) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69589) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Denial of Service vulnerability
Windows TCP/IP Denial of Service vulnerability (CVE-2026-69588) was added to Microsoft’s security update guidance. Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Windows Internet Key Exchange (IKE) Extension Denial of Service vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service vulnerability (CVE-2026-69587) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows PDF Remote Code Execution vulnerability
Microsoft Windows PDF Remote Code Execution vulnerability (CVE-2026-69586) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Elevation of Privilege vulnerability
Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69585) was added to Microsoft’s security update guidance. <p>Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Video Driver Elevation of Privilege vulnerability
Windows USB Video Driver Elevation of Privilege vulnerability (CVE-2026-69584) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69583) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Volume Manager Extension Driver Elevation of Privilege vulnerability
Windows Volume Manager Extension Driver Elevation of Privilege vulnerability (CVE-2026-69582) was added to Microsoft’s security update guidance. <p>Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.