Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69581) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69580) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Message Queuing Remote Code Execution vulnerability
Windows Message Queuing Remote Code Execution vulnerability (CVE-2026-69579) was added to Microsoft’s security update guidance. <p>Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-69578) was added to Microsoft’s security update guidance. Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Storage Spaces Controller Elevation of Privilege vulnerability
Windows Storage Spaces Controller Elevation of Privilege vulnerability (CVE-2026-69575) was added to Microsoft’s security update guidance. <p>Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69574) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability (CVE-2026-69573) was added to Microsoft’s security update guidance. <p>Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows SMB Client Information Disclosure vulnerability
Windows SMB Client Information Disclosure vulnerability (CVE-2026-69572) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69571) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Denial of Service vulnerability
Windows Print Spooler Components Denial of Service vulnerability (CVE-2026-69569) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69567) was added to Microsoft’s security update guidance. Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-69566) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. If you need help checking exposure, call (864) 335-9223.
Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege vulnerability
Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege vulnerability (CVE-2026-69564) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Program Compatibility Assistant Service Elevation of Privilege vulnerability
Windows Program Compatibility Assistant Service Elevation of Privilege vulnerability (CVE-2026-69563) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-69562) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows CD-ROM Driver Elevation of Privilege vulnerability
Windows CD-ROM Driver Elevation of Privilege vulnerability (CVE-2026-69561) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Work Folder Service Elevation of Privilege vulnerability
Windows Work Folder Service Elevation of Privilege vulnerability (CVE-2026-69560) was added to Microsoft’s security update guidance. <p>Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Teams for Android Information Disclosure vulnerability
Microsoft Teams for Android Information Disclosure vulnerability (CVE-2026-69559) was added to Microsoft’s security update guidance. Corrected fix build number. Informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69556) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Tampering vulnerability
Microsoft Windows Search Component Tampering vulnerability (CVE-2026-69554) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Elevation of Privilege vulnerability
Windows Hyper-V Elevation of Privilege vulnerability (CVE-2026-69553) was added to Microsoft’s security update guidance. <p>Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Information Disclosure vulnerability
Windows Print Spooler Components Information Disclosure vulnerability (CVE-2026-69552) was added to Microsoft’s security update guidance. Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69551) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows RNDIS Information Disclosure vulnerability
Windows RNDIS Information Disclosure vulnerability (CVE-2026-69548) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.