Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-69298

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69298) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69297

Windows DHCP Server Information Disclosure vulnerability

Windows DHCP Server Information Disclosure vulnerability (CVE-2026-69297) was added to Microsoft’s security update guidance. Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69296

Windows Device Association Service Elevation of Privilege vulnerability

Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69296) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69295

Windows USB Driver Elevation of Privilege vulnerability

Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-69295) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69294

Microsoft COM for Windows Information Disclosure vulnerability

Microsoft COM for Windows Information Disclosure vulnerability (CVE-2026-69294) was added to Microsoft’s security update guidance. <p>Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69293

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69293) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69291

Windows Volume Manager Extension Driver Remote Code Execution vulnerability

Windows Volume Manager Extension Driver Remote Code Execution vulnerability (CVE-2026-69291) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69290

Windows Storage Spaces Controller Elevation of Privilege vulnerability

Windows Storage Spaces Controller Elevation of Privilege vulnerability (CVE-2026-69290) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69289

Windows Setup Files Cleanup Elevation of Privilege vulnerability

Windows Setup Files Cleanup Elevation of Privilege vulnerability (CVE-2026-69289) was added to Microsoft’s security update guidance. <p>Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69288

Windows GDI+ Information Disclosure vulnerability

Windows GDI+ Information Disclosure vulnerability (CVE-2026-69288) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69287

Windows Remote Desktop Services Elevation of Privilege vulnerability

Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-69287) was added to Microsoft’s security update guidance. <p>Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69286

Windows USB Audio Class Driver Information Disclosure vulnerability

Windows USB Audio Class Driver Information Disclosure vulnerability (CVE-2026-69286) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69285

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-69285) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69284

Windows DCOM Server Elevation of Privilege vulnerability

Windows DCOM Server Elevation of Privilege vulnerability (CVE-2026-69284) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69283

Windows CD-ROM Driver Elevation of Privilege vulnerability

Windows CD-ROM Driver Elevation of Privilege vulnerability (CVE-2026-69283) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69282

Microsoft Office SharePoint Remote Code Execution vulnerability

Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69282) was added to Microsoft’s security update guidance. <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69281

Windows License Manager Elevation of Privilege vulnerability

Windows License Manager Elevation of Privilege vulnerability (CVE-2026-69281) was added to Microsoft’s security update guidance. <p>Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69280

Windows Push Notifications Elevation of Privilege vulnerability

Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-69280) was added to Microsoft’s security update guidance. <p>Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69279

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-69279) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69277

Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability

Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability (CVE-2026-69277) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69276

Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution vulnerability

Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution vulnerability (CVE-2026-69276) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69274

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69274) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69273

Microsoft Office SharePoint Remote Code Execution vulnerability

Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69273) was added to Microsoft’s security update guidance. <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69272

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69272) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.