Autor: Peter Leibling

CVE-2026-0390 UEFI Secure Boot Security Feature Bypass Vulnerability

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2023-20585 AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability

The vulnerability assigned to this CVE could lead to corruption of guest encrypted memory. The mitigation for this vulnerability requires a Windows update. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and provide protection against the vulnerability. Please see the following for…
Weiterlesen

CVE-2026-26162 Windows OLE Elevation of Privilege Vulnerability

Access of resource using incompatible type (‚type confusion‘) in Windows OLE allows an authorized attacker to elevate privileges locally.

CVE-2026-32222 Windows Win32k Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Win32K – ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-32220 UEFI Secure Boot Security Feature Bypass Vulnerability

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

CVE-2026-32178 .NET Spoofing Vulnerability

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-26165 Windows Shell Elevation of Privilege Vulnerability

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-26166 Windows Shell Elevation of Privilege Vulnerability

Double free in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-32176 SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command (’sql injection‘) in SQL Server allows an authorized attacker to elevate privileges locally.

CVE-2026-32072 Active Directory Spoofing Vulnerability

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.