Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69298) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Information Disclosure vulnerability
Windows DHCP Server Information Disclosure vulnerability (CVE-2026-69297) was added to Microsoft’s security update guidance. Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69296) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Driver Elevation of Privilege vulnerability
Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-69295) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft COM for Windows Information Disclosure vulnerability
Microsoft COM for Windows Information Disclosure vulnerability (CVE-2026-69294) was added to Microsoft’s security update guidance. <p>Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69293) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Volume Manager Extension Driver Remote Code Execution vulnerability
Windows Volume Manager Extension Driver Remote Code Execution vulnerability (CVE-2026-69291) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Storage Spaces Controller Elevation of Privilege vulnerability
Windows Storage Spaces Controller Elevation of Privilege vulnerability (CVE-2026-69290) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Setup Files Cleanup Elevation of Privilege vulnerability
Windows Setup Files Cleanup Elevation of Privilege vulnerability (CVE-2026-69289) was added to Microsoft’s security update guidance. <p>Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows GDI+ Information Disclosure vulnerability
Windows GDI+ Information Disclosure vulnerability (CVE-2026-69288) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-69287) was added to Microsoft’s security update guidance. <p>Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class Driver Information Disclosure vulnerability
Windows USB Audio Class Driver Information Disclosure vulnerability (CVE-2026-69286) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-69285) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DCOM Server Elevation of Privilege vulnerability
Windows DCOM Server Elevation of Privilege vulnerability (CVE-2026-69284) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows CD-ROM Driver Elevation of Privilege vulnerability
Windows CD-ROM Driver Elevation of Privilege vulnerability (CVE-2026-69283) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Remote Code Execution vulnerability
Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69282) was added to Microsoft’s security update guidance. <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows License Manager Elevation of Privilege vulnerability
Windows License Manager Elevation of Privilege vulnerability (CVE-2026-69281) was added to Microsoft’s security update guidance. <p>Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Push Notifications Elevation of Privilege vulnerability
Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-69280) was added to Microsoft’s security update guidance. <p>Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-69279) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability
Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability (CVE-2026-69277) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution vulnerability
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution vulnerability (CVE-2026-69276) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69274) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Remote Code Execution vulnerability
Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69273) was added to Microsoft’s security update guidance. <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Elevation of Privilege vulnerability
Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69272) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.