Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-62729

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62729) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62726

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62726) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62725

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62725) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62724

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62724) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62723

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62723) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62722

Microsoft Brokering File System Elevation of Privilege vulnerability

Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-62722) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62719

Windows Message Queuing Elevation of Privilege vulnerability

Windows Message Queuing Elevation of Privilege vulnerability (CVE-2026-62719) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62713

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-62713) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62712

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-62712) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62711

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-62711) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62710

Windows Device Association Service Elevation of Privilege vulnerability

Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-62710) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62709

Windows GDI+ Information Disclosure vulnerability

Windows GDI+ Information Disclosure vulnerability (CVE-2026-62709) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62708

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62708) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62707

Windows Modern Device Management (MDM) Elevation of Privilege vulnerability

Windows Modern Device Management (MDM) Elevation of Privilege vulnerability (CVE-2026-62707) was added to Microsoft’s security update guidance. Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62705

Microsoft Brokering File System Elevation of Privilege vulnerability

Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-62705) was added to Microsoft’s security update guidance. Corrected the CVE title from **Windows Bind Filter Driver Elevation of Privilege Vulnerability** to **Microsoft Brokering File System Elevation of Privilege Vulnerability** and updated the acknowledgement. These are informational changes only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62702

Windows Graphics Kernel Denial of Service vulnerability

Windows Graphics Kernel Denial of Service vulnerability (CVE-2026-62702) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62701

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-62701) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62700

Windows NTFS Elevation of Privilege vulnerability

Windows NTFS Elevation of Privilege vulnerability (CVE-2026-62700) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62699

Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution vulnerability

Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution vulnerability (CVE-2026-62699) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62698

Microsoft Digest Authentication Elevation of Privilege vulnerability

Microsoft Digest Authentication Elevation of Privilege vulnerability (CVE-2026-62698) was added to Microsoft’s security update guidance. Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62692

Windows Remote Desktop Services Elevation of Privilege vulnerability

Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-62692) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62690

Windows Push Notifications Elevation of Privilege vulnerability

Windows Push Notifications Elevation of Privilege vulnerability (CVE-2026-62690) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61938

Windows Installer Elevation of Privilege vulnerability

Windows Installer Elevation of Privilege vulnerability (CVE-2026-61938) was added to Microsoft’s security update guidance. Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61937

Windows HTTP.sys Elevation of Privilege vulnerability

Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-61937) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.