Autor: Peter Leibling

CVE-2026-32220 UEFI Secure Boot Security Feature Bypass Vulnerability

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

CVE-2026-0390 UEFI Secure Boot Security Feature Bypass Vulnerability

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2026-32222 Windows Win32k Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Win32K – ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-32217 Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-32176 SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command (’sql injection‘) in SQL Server allows an authorized attacker to elevate privileges locally.

CVE-2026-32200 Microsoft PowerPoint Remote Code Execution Vulnerability

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2026-26162 Windows OLE Elevation of Privilege Vulnerability

Access of resource using incompatible type (‚type confusion‘) in Windows OLE allows an authorized attacker to elevate privileges locally.

CVE-2026-32224 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

CVE-2026-26167 Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-32088 Windows Biometric Service Security Feature Bypass Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.