Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-69504) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows USB Driver Elevation of Privilege vulnerability
Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-69503) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows Secure Kernel Mode Elevation of Privilege vulnerability
Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-69501) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Image Acquisition Elevation of Privilege vulnerability
Windows Image Acquisition Elevation of Privilege vulnerability (CVE-2026-69500) was added to Microsoft’s security update guidance. <p>Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Remote Code Execution vulnerability
Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-69499) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69498) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-69497) was added to Microsoft’s security update guidance. <p>Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Compressed Folder Remote Code Execution vulnerability
Windows Compressed Folder Remote Code Execution vulnerability (CVE-2026-69496) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Event Logging Service Remote Code Execution vulnerability
Windows Event Logging Service Remote Code Execution vulnerability (CVE-2026-69495) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Event Logging Service Remote Code Execution vulnerability
Windows Event Logging Service Remote Code Execution vulnerability (CVE-2026-69494) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Event Logging Service Remote Code Execution vulnerability
Windows Event Logging Service Remote Code Execution vulnerability (CVE-2026-69493) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft DirectMusic Remote Code Execution vulnerability
Microsoft DirectMusic Remote Code Execution vulnerability (CVE-2026-69491) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Mass Storage Class Driver Elevation of Privilege vulnerability
Windows USB Mass Storage Class Driver Elevation of Privilege vulnerability (CVE-2026-69490) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69489) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69488) was added to Microsoft’s security update guidance. Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Image Acquisition Information Disclosure vulnerability
Windows Image Acquisition Information Disclosure vulnerability (CVE-2026-69483) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Tampering vulnerability
Windows Error Reporting Tampering vulnerability (CVE-2026-69482) was added to Microsoft’s security update guidance. <p>Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Enterprise App Management Elevation of Privilege vulnerability
Windows Enterprise App Management Elevation of Privilege vulnerability (CVE-2026-69481) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Partition Management Driver Elevation of Privilege vulnerability
Windows Partition Management Driver Elevation of Privilege vulnerability (CVE-2026-69480) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-69479) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69478) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Access Remote Code Execution vulnerability
Microsoft Office Access Remote Code Execution vulnerability (CVE-2026-69477) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69476) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-69475) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.