Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Remote Access Connection Manager Elevation of Privilege vulnerability
Windows Remote Access Connection Manager Elevation of Privilege vulnerability (CVE-2026-69331) was added to Microsoft’s security update guidance. Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Storage Elevation of Privilege vulnerability
Windows Storage Elevation of Privilege vulnerability (CVE-2026-69328) was added to Microsoft’s security update guidance. <p>Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft JScript Remote Code Execution vulnerability
Microsoft JScript Remote Code Execution vulnerability (CVE-2026-69325) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Performance Monitor Elevation of Privilege vulnerability
Windows Performance Monitor Elevation of Privilege vulnerability (CVE-2026-69324) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69323) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Elevation of Privilege vulnerability
Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69322) was added to Microsoft’s security update guidance. <p>Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Power Dependency Coordinator Tampering vulnerability
Windows Power Dependency Coordinator Tampering vulnerability (CVE-2026-69321) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows USB Video Driver Elevation of Privilege vulnerability
Windows USB Video Driver Elevation of Privilege vulnerability (CVE-2026-69319) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Information Disclosure vulnerability
Windows Imaging Component Information Disclosure vulnerability (CVE-2026-69318) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-69317) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Information Disclosure vulnerability
Windows Overlay Filter Information Disclosure vulnerability (CVE-2026-69316) was added to Microsoft’s security update guidance. Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows License Manager Information Disclosure vulnerability
Windows License Manager Information Disclosure vulnerability (CVE-2026-69315) was added to Microsoft’s security update guidance. <p>Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Broker Service Elevation of Privilege vulnerability
Windows Device Association Broker Service Elevation of Privilege vulnerability (CVE-2026-69314) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Elevation of Privilege vulnerability
Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69313) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69312) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Audio Service Elevation of Privilege vulnerability
Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69311) was added to Microsoft’s security update guidance. <p>Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-69310) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Elevation of Privilege vulnerability
Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-69309) was added to Microsoft’s security update guidance. <p>Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Information Disclosure vulnerability
Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-69308) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69307) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Elevation of Privilege vulnerability
Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69305) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69301) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Push Notifications Elevation of Privilege vulnerability
Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-69300) was added to Microsoft’s security update guidance. <p>Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft COM for Windows Elevation of Privilege vulnerability
Microsoft COM for Windows Elevation of Privilege vulnerability (CVE-2026-69299) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.