Microsoft security briefs
3324 published alerts for Microsoft products and services.
Windows Graphics Kernel Elevation of Privilege vulnerability
Windows Graphics Kernel Elevation of Privilege vulnerability (CVE-2026-62774) was added to Microsoft’s security update guidance. Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Elevation of Privilege vulnerability
Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62773) was added to Microsoft’s security update guidance. Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-62771) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Shell Elevation of Privilege vulnerability
Windows Shell Elevation of Privilege vulnerability (CVE-2026-62770) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-62769) was added to Microsoft’s security update guidance. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Elevation of Privilege vulnerability
Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62766) was added to Microsoft’s security update guidance. Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Access Connection Manager Elevation of Privilege vulnerability
Windows Remote Access Connection Manager Elevation of Privilege vulnerability (CVE-2026-62758) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Schannel Security Feature Bypass vulnerability
Windows Schannel Security Feature Bypass vulnerability (CVE-2026-62757) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Elevation of Privilege vulnerability
Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62752) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Projected File System Elevation of Privilege vulnerability
Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-62751) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows HTTP Protocol Stack Tampering vulnerability
Windows HTTP Protocol Stack Tampering vulnerability (CVE-2026-62750) was added to Microsoft’s security update guidance. Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62749) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62748) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows HTTP.sys Elevation of Privilege vulnerability
Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62741) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Information Disclosure vulnerability
Windows Imaging Component Information Disclosure vulnerability (CVE-2026-62740) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows HTTP.sys Elevation of Privilege vulnerability
Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62739) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Management Instrumentation Information Disclosure vulnerability
Windows Management Instrumentation Information Disclosure vulnerability (CVE-2026-62738) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62737) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Elevation of Privilege vulnerability
Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-62736) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows HTTP.sys Elevation of Privilege vulnerability
Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62735) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62734) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-62733) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62732) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Wired AutoConfig Service Information Disclosure vulnerability
Windows Wired AutoConfig Service Information Disclosure vulnerability (CVE-2026-62730) was added to Microsoft’s security update guidance. Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.