Microsoft security briefs
3324 published alerts for Microsoft products and services.
Windows Notification Elevation of Privilege vulnerability
Windows Notification Elevation of Privilege vulnerability (CVE-2026-50337) was added to Microsoft’s security update guidance. Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Media Elevation of Privilege vulnerability
Windows Media Elevation of Privilege vulnerability (CVE-2026-50336) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Operating Systems Elevation of Privilege vulnerability
Windows Operating Systems Elevation of Privilege vulnerability (CVE-2026-50335) was added to Microsoft’s security update guidance. Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Push Notification Information Disclosure vulnerability
Windows Push Notification Information Disclosure vulnerability (CVE-2026-50334) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50332) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Application Model Core API Elevation of Privilege vulnerability
Windows Application Model Core API Elevation of Privilege vulnerability (CVE-2026-50331) was added to Microsoft’s security update guidance. Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Elevation of Privilege vulnerability
Windows Remote Desktop Client Elevation of Privilege vulnerability (CVE-2026-50330) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft DWM Core Library Elevation of Privilege vulnerability
Microsoft DWM Core Library Elevation of Privilege vulnerability (CVE-2026-50329) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Server Update Service (WSUS) Tampering vulnerability
Windows Server Update Service (WSUS) Tampering vulnerability (CVE-2026-50328) was added to Microsoft’s security update guidance. Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.
Windows Media Remote Code Execution vulnerability
Windows Media Remote Code Execution vulnerability (CVE-2026-50327) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Unified Consent System Elevation of Privilege vulnerability
Windows Unified Consent System Elevation of Privilege vulnerability (CVE-2026-50326) was added to Microsoft’s security update guidance. Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Runtime Elevation of Privilege vulnerability
Windows Runtime Elevation of Privilege vulnerability (CVE-2026-50323) was added to Microsoft’s security update guidance. Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Runtime Elevation of Privilege vulnerability
Windows Runtime Elevation of Privilege vulnerability (CVE-2026-50322) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows USB Driver Elevation of Privilege vulnerability
Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-50321) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50318) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Operating Systems Elevation of Privilege vulnerability
Windows Operating Systems Elevation of Privilege vulnerability (CVE-2026-50317) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Information Disclosure vulnerability
Windows Kernel Information Disclosure vulnerability (CVE-2026-50316) was added to Microsoft’s security update guidance. Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Image Acquisition Elevation of Privilege vulnerability
Windows Image Acquisition Elevation of Privilege vulnerability (CVE-2026-50315) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-50314) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-50312) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Human Interface Device Information Disclosure vulnerability
Windows Human Interface Device Information Disclosure vulnerability (CVE-2026-50310) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-50308) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-50307) was added to Microsoft’s security update guidance. Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-50306) was added to Microsoft’s security update guidance. Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.