Autor: Peter Leibling

CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-23669 Windows Print Spooler Remote Code Execution Vulnerability

Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVE-2026-26115 SQL Server Elevation of Privilege Vulnerability

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-23671 Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability

Improper neutralization of input during web page generation (‚cross-site scripting‘) in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVE-2026-26113 Microsoft Office Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-23674 MapUrlToZone Security Feature Bypass Vulnerability

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-26112 Microsoft Excel Remote Code Execution Vulnerability

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-25190 GDI Remote Code Execution Vulnerability

Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

[NEU] [kritisch] Budibase: Mehrere Schwachstellen

Ein Angreifer kann eine Schwachstelle in Budibase ausnutzen, um Dateien zu manipulieren, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.