Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-62774

Windows Graphics Kernel Elevation of Privilege vulnerability

Windows Graphics Kernel Elevation of Privilege vulnerability (CVE-2026-62774) was added to Microsoft’s security update guidance. Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62773

Windows Kerberos Elevation of Privilege vulnerability

Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62773) was added to Microsoft’s security update guidance. Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62771

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-62771) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62770

Windows Shell Elevation of Privilege vulnerability

Windows Shell Elevation of Privilege vulnerability (CVE-2026-62770) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62769

Windows DNS Elevation of Privilege vulnerability

Windows DNS Elevation of Privilege vulnerability (CVE-2026-62769) was added to Microsoft’s security update guidance. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62766

Windows Kerberos Elevation of Privilege vulnerability

Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62766) was added to Microsoft’s security update guidance. Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62758

Windows Remote Access Connection Manager Elevation of Privilege vulnerability

Windows Remote Access Connection Manager Elevation of Privilege vulnerability (CVE-2026-62758) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62757

Windows Schannel Security Feature Bypass vulnerability

Windows Schannel Security Feature Bypass vulnerability (CVE-2026-62757) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62752

Windows Kerberos Elevation of Privilege vulnerability

Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62752) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62751

Windows Projected File System Elevation of Privilege vulnerability

Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-62751) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62750

Windows HTTP Protocol Stack Tampering vulnerability

Windows HTTP Protocol Stack Tampering vulnerability (CVE-2026-62750) was added to Microsoft’s security update guidance. Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62749

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62749) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62748

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62748) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62741

Windows HTTP.sys Elevation of Privilege vulnerability

Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62741) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62740

Windows Imaging Component Information Disclosure vulnerability

Windows Imaging Component Information Disclosure vulnerability (CVE-2026-62740) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62739

Windows HTTP.sys Elevation of Privilege vulnerability

Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62739) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62738

Windows Management Instrumentation Information Disclosure vulnerability

Windows Management Instrumentation Information Disclosure vulnerability (CVE-2026-62738) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62737

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62737) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62736

Windows DHCP Client Elevation of Privilege vulnerability

Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-62736) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62735

Windows HTTP.sys Elevation of Privilege vulnerability

Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62735) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62734

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62734) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62733

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-62733) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62732

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62732) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62730

Windows Wired AutoConfig Service Information Disclosure vulnerability

Windows Wired AutoConfig Service Information Disclosure vulnerability (CVE-2026-62730) was added to Microsoft’s security update guidance. Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.