Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69478) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Access Remote Code Execution vulnerability
Microsoft Office Access Remote Code Execution vulnerability (CVE-2026-69477) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69476) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-69475) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Information Disclosure vulnerability
Windows Overlay Filter Information Disclosure vulnerability (CVE-2026-69474) was added to Microsoft’s security update guidance. Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-69473) was added to Microsoft’s security update guidance. <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Devices Human Interface Elevation of Privilege vulnerability
Windows Devices Human Interface Elevation of Privilege vulnerability (CVE-2026-69472) was added to Microsoft’s security update guidance. <p>Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69469) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.
Windows Volume Manager Extension Driver Elevation of Privilege vulnerability
Windows Volume Manager Extension Driver Elevation of Privilege vulnerability (CVE-2026-69468) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Graphics Component Elevation of Privilege vulnerability
Microsoft Graphics Component Elevation of Privilege vulnerability (CVE-2026-69467) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-69466) was added to Microsoft’s security update guidance. <p>Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Remote Code Execution vulnerability
Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69465) was added to Microsoft’s security update guidance. <p>Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Elevation of Privilege vulnerability
Microsoft Office SharePoint Elevation of Privilege vulnerability (CVE-2026-69464) was added to Microsoft’s security update guidance. <p>Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-69463) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Elevation of Privilege vulnerability
Windows Error Reporting Elevation of Privilege vulnerability (CVE-2026-69462) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-69461) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Modern Device Management (MDM) Elevation of Privilege vulnerability
Windows Modern Device Management (MDM) Elevation of Privilege vulnerability (CVE-2026-69460) was added to Microsoft’s security update guidance. <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Power Dependency Coordinator Elevation of Privilege vulnerability
Windows Power Dependency Coordinator Elevation of Privilege vulnerability (CVE-2026-69459) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows BitLocker Elevation of Privilege vulnerability
Windows BitLocker Elevation of Privilege vulnerability (CVE-2026-69458) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Driver Information Disclosure vulnerability
Windows USB Driver Information Disclosure vulnerability (CVE-2026-69457) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Speech Elevation of Privilege vulnerability
Microsoft Windows Speech Elevation of Privilege vulnerability (CVE-2026-69456) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Access Connection Manager Elevation of Privilege vulnerability
Windows Remote Access Connection Manager Elevation of Privilege vulnerability (CVE-2026-69455) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Tampering vulnerability
Microsoft Windows Search Component Tampering vulnerability (CVE-2026-69453) was added to Microsoft’s security update guidance. <p>Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Management Instrumentation Elevation of Privilege vulnerability
Windows Management Instrumentation Elevation of Privilege vulnerability (CVE-2026-69451) was added to Microsoft’s security update guidance. <p>Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.