Autor: Peter Leibling

CVE-2026-32159 Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-33096 HTTP.sys Denial of Service Vulnerability

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVE-2026-32083 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

CVE-2026-26143 Microsoft PowerShell Security Feature Bypass Vulnerability

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-32087 Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-32073 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-32091 Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

CVE-2026-32164 Windows User Interface Core Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-27931 Windows GDI Information Disclosure Vulnerability

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

CVE-2026-32183 Windows Snipping Tool Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command (‚command injection‘) in Windows Snipping Tool allows an unauthorized attacker to execute code locally.