Kategorie: Allgemein

CVE-2026-23664 Azure IoT Explorer Information Disclosure Vulnerability

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.

CVE-2026-26114 Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-24282 Push message Routing Service Elevation of Privilege Vulnerability

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

CVE-2026-23673 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-23669 Windows Print Spooler Remote Code Execution Vulnerability

Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability

Improper neutralization of input during web page generation (‚cross-site scripting‘) in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.