Kategorie: Allgemein

CVE-2026-25166 Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

CVE-2026-24297 Windows Kerberos Security Feature Bypass Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-25170 Windows Hyper-V Elevation of Privilege Vulnerability

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-26130 ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-23673 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability

Improper link resolution before file access (‚link following‘) in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-23669 Windows Print Spooler Remote Code Execution Vulnerability

Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability

Improper neutralization of input during web page generation (‚cross-site scripting‘) in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVE-2026-23671 Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization (‚race condition‘) in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-26115 SQL Server Elevation of Privilege Vulnerability

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.