Autor: Peter Leibling

CVE-2026-27931 Windows GDI Information Disclosure Vulnerability

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

CVE-2026-33104 Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-32085 Remote Procedure Call Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.

CVE-2026-25250 MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix

Missing cryptographic step in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-33099 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-33114 Microsoft Word Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-32076 Windows Storage Spaces Controller Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVE-2026-26178 Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability

Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.

CVE-2026-33827 Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.