Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-69331

Windows Remote Access Connection Manager Elevation of Privilege vulnerability

Windows Remote Access Connection Manager Elevation of Privilege vulnerability (CVE-2026-69331) was added to Microsoft’s security update guidance. Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69328

Windows Storage Elevation of Privilege vulnerability

Windows Storage Elevation of Privilege vulnerability (CVE-2026-69328) was added to Microsoft’s security update guidance. <p>Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69325

Microsoft JScript Remote Code Execution vulnerability

Microsoft JScript Remote Code Execution vulnerability (CVE-2026-69325) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69324

Windows Performance Monitor Elevation of Privilege vulnerability

Windows Performance Monitor Elevation of Privilege vulnerability (CVE-2026-69324) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69323

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69323) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69322

Microsoft Windows Search Component Elevation of Privilege vulnerability

Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69322) was added to Microsoft’s security update guidance. <p>Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69321

Windows Power Dependency Coordinator Tampering vulnerability

Windows Power Dependency Coordinator Tampering vulnerability (CVE-2026-69321) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69319

Windows USB Video Driver Elevation of Privilege vulnerability

Windows USB Video Driver Elevation of Privilege vulnerability (CVE-2026-69319) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69318

Windows Imaging Component Information Disclosure vulnerability

Windows Imaging Component Information Disclosure vulnerability (CVE-2026-69318) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69317

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-69317) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69316

Windows Overlay Filter Information Disclosure vulnerability

Windows Overlay Filter Information Disclosure vulnerability (CVE-2026-69316) was added to Microsoft’s security update guidance. Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69315

Windows License Manager Information Disclosure vulnerability

Windows License Manager Information Disclosure vulnerability (CVE-2026-69315) was added to Microsoft’s security update guidance. <p>Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69314

Windows Device Association Broker Service Elevation of Privilege vulnerability

Windows Device Association Broker Service Elevation of Privilege vulnerability (CVE-2026-69314) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69313

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69313) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69312

Windows NTFS Elevation of Privilege vulnerability

Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69312) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69311

Windows Audio Service Elevation of Privilege vulnerability

Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69311) was added to Microsoft’s security update guidance. <p>Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69310

Windows DNS Elevation of Privilege vulnerability

Windows DNS Elevation of Privilege vulnerability (CVE-2026-69310) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69309

Windows Print Spooler Components Elevation of Privilege vulnerability

Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-69309) was added to Microsoft’s security update guidance. <p>Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69308

Microsoft Standard XPS Information Disclosure vulnerability

Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-69308) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69307

Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability

Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69307) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69305

Microsoft Windows Search Component Elevation of Privilege vulnerability

Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69305) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69301

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69301) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69300

Windows Push Notifications Elevation of Privilege vulnerability

Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-69300) was added to Microsoft’s security update guidance. <p>Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69299

Microsoft COM for Windows Elevation of Privilege vulnerability

Microsoft COM for Windows Elevation of Privilege vulnerability (CVE-2026-69299) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.