Autor: Peter Leibling

CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.

CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-26108 Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-23668 Windows Graphics Component Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

CVE-2026-26127 .NET Denial of Service Vulnerability

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

CVE-2026-23667 Broadcast DVR Elevation of Privilege Vulnerability

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

CVE-2026-26105 Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation (‚cross-site scripting‘) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-23664 Azure IoT Explorer Information Disclosure Vulnerability

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-25166 Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.