Description
Multiple vulnerabilities were found in Microsoft Products (ESU). Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, gain privileges, obtain sensitive information, perform cross-site scripting attack, spoof user interface.
Below is a complete list of vulnerabilities:
- An elevation of privilege vulnerability in Remote Access Management service/API (RPC server) can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Windows Active Directory Domain Services can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows LUA File Virtualization Filter Driver can be exploited remotely to gain privileges.
- A denial of service vulnerability in Remote Procedure Call can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Windows Imaging Component can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows Narrator Braille can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Telephony Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Remote Desktop Services can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Event Logging Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Installer can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows Encrypting File System (EFS) can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in AMD Zen can be exploited remotely to obtain sensitive information.
- A denial of service vulnerability in Windows TCP/IP can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Remote Desktop Client can be exploited remotely to execute arbitrary code.
- An information disclosure vulnerability in Microsoft Windows Search Component can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Microsoft COM for Windows can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Windows Event Logging Service can be exploited remotely to obtain sensitive information.
- A denial of service vulnerability in Microsoft Remote Registry Service can be exploited remotely to cause denial of service.
- An elevation of privilege vulnerability in Windows Graphics Kernel can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Ancillary Function Driver for WinSock can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Work Folder Service can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows NTFS can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Sensor Data Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Accessibility Infrastructure (ATBroker.exe) can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows GDI can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Network Connection Broker can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows Hyper-V can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Windows Remote Desktop Client can be exploited remotely to obtain sensitive information.
- A remote code execution vulnerability in Windows DNS Server can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows Display Enhancement Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows USB Driver can be exploited remotely to gain privileges.
- A tampering vulnerability in Windows Hello can be exploited remotely to spoof user interface.
- An elevation of privilege vulnerability in Windows Kernel can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows DWM Core Library can be exploited remotely to gain privileges.
- A security feature bypass vulnerability in Windows Defender Firewall Service can be exploited remotely to bypass security restrictions.
- An elevation of privilege vulnerability in Windows HTTP.sys can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Winlogon can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Push Notifications can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Program Compatibility Assistant Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Digest Authentication can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Windows Universal Disk Format File System Driver (UDFS) can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows NTFS can be exploited remotely to gain privileges.
- A denial of service vulnerability in Windows Graphics Kernel can be exploited remotely to cause denial of service.
- An information disclosure vulnerability in Windows DWM Core Library can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Modern Device Management (MDM) can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows GDI+ can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Device Association Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Win32k can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Cloud Files Mini Filter Driver can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows DHCP Server can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Message Queuing can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows User-Mode Power Service (UMPS) can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Common Log File System Driver can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows Wired AutoConfig Service can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Windows Management Instrumentation can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Windows Imaging Component can be exploited remotely to obtain sensitive information.
- An information disclosure vulnerability in Win32k can be exploited remotely to obtain sensitive information.
- A tampering vulnerability in Windows HTTP Protocol Stack can be exploited remotely to spoof user interface.
- An elevation of privilege vulnerability in Windows Projected File System can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Kerberos can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows DHCP Client can be exploited remotely to gain privileges.
- A security feature bypass vulnerability in Windows Schannel can be exploited remotely to bypass security restrictions.
- An elevation of privilege vulnerability in Windows Remote Access Connection Manager can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows DHCP Server can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows DNS can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Shell can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows License Manager can be exploited remotely to gain privileges.
- A remote code execution vulnerability in RPC Runtime Library can be exploited remotely to execute arbitrary code.
- An information disclosure vulnerability in Windows SMB Client can be exploited remotely to obtain sensitive information.
- A remote code execution vulnerability in Microsoft Local Security Authority Server (lsasrv) can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows LDAP – Lightweight Directory Access Protocol can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows SMBv3 Server can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows TCP/IP can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows Reliable Multicast Transport Driver (RMCAST) can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows Active Directory Certificate Services (AD CS) can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows Routing and Remote Access Service (RRAS) can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows GDI+ can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Windows DHCP Server can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows User Profile Service can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows GDI+ can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Capability Access Management Service (camsvc) can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Windows Deployment Services TFTP Server can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows Backup Engine can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Exchange Server can be exploited remotely to gain privileges.
- A denial of service vulnerability in Microsoft Exchange Server can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Microsoft Exchange Server can be exploited remotely to execute arbitrary code.
- A spoofing vulnerability in Microsoft Exchange Server can be exploited remotely to spoof user interface.
- A security feature bypass vulnerability in Microsoft Exchange Server can be exploited remotely to bypass security restrictions.
- An elevation of privilege vulnerability in Remote Access API can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Windows iSCSI Target Service can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Desktop Window Manager can be exploited remotely to gain privileges.
- A denial of service vulnerability in Windows iSCSI Target Service can be exploited remotely to cause denial of service.
- An elevation of privilege vulnerability in Microsoft Windows Storage Port Driver can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Key Guard can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Windows Cross Device Service can be exploited remotely to gain privileges.
- Security UI vulnerability can be exploited to spoof user interface.
- A denial of service vulnerability in Windows Network File System can be exploited remotely to cause denial of service.
Original advisories
- CVE-2026-49179
- CVE-2026-50472
- CVE-2026-54113
- CVE-2026-54984
- CVE-2026-56174
- CVE-2026-59122
- CVE-2026-59125
- CVE-2026-59126
- CVE-2026-59127
- CVE-2026-59128
- CVE-2026-59130
- CVE-2026-59131
- CVE-2026-59132
- CVE-2026-59134
- CVE-2026-59135
- CVE-2026-59136
- CVE-2026-59137
- CVE-2026-59138
- CVE-2026-61345
- CVE-2026-61346
- CVE-2026-61347
- CVE-2026-61348
- CVE-2026-61349
- CVE-2026-61350
- CVE-2026-61352
- CVE-2026-61353
- CVE-2026-61355
- CVE-2026-61356
- CVE-2026-61358
- CVE-2026-61360
- CVE-2026-61363
- CVE-2026-61364
- CVE-2026-61365
- CVE-2026-61366
- CVE-2026-61367
- CVE-2026-61368
- CVE-2026-61918
- CVE-2026-61920
- CVE-2026-61921
- CVE-2026-61923
- CVE-2026-61924
- CVE-2026-61925
- CVE-2026-61926
- CVE-2026-61928
- CVE-2026-61930
- CVE-2026-61932
- CVE-2026-61936
- CVE-2026-61937
- CVE-2026-61939
- CVE-2026-62690
- CVE-2026-62692
- CVE-2026-62696
- CVE-2026-62698
- CVE-2026-62699
- CVE-2026-62700
- CVE-2026-62701
- CVE-2026-62702
- CVE-2026-62703
- CVE-2026-62707
- CVE-2026-62709
- CVE-2026-62710
- CVE-2026-62711
- CVE-2026-62712
- CVE-2026-62713
- CVE-2026-62714
- CVE-2026-62715
- CVE-2026-62716
- CVE-2026-62717
- CVE-2026-62718
- CVE-2026-62719
- CVE-2026-62720
- CVE-2026-62721
- CVE-2026-62723
- CVE-2026-62724
- CVE-2026-62725
- CVE-2026-62726
- CVE-2026-62728
- CVE-2026-62729
- CVE-2026-62730
- CVE-2026-62732
- CVE-2026-62733
- CVE-2026-62734
- CVE-2026-62735
- CVE-2026-62738
- CVE-2026-62739
- CVE-2026-62740
- CVE-2026-62741
- CVE-2026-62742
- CVE-2026-62743
- CVE-2026-62745
- CVE-2026-62746
- CVE-2026-62747
- CVE-2026-62748
- CVE-2026-62750
- CVE-2026-62751
- CVE-2026-62752
- CVE-2026-62753
- CVE-2026-62754
- CVE-2026-62755
- CVE-2026-62757
- CVE-2026-62758
- CVE-2026-62761
- CVE-2026-62768
- CVE-2026-62769
- CVE-2026-62770
- CVE-2026-62771
- CVE-2026-62773
- CVE-2026-62774
- CVE-2026-62776
- CVE-2026-62777
- CVE-2026-62778
- CVE-2026-62781
- CVE-2026-62782
- CVE-2026-62783
- CVE-2026-62784
- CVE-2026-62785
- CVE-2026-62786
- CVE-2026-62787
- CVE-2026-62790
- CVE-2026-62792
- CVE-2026-62793
- CVE-2026-62795
- CVE-2026-62796
- CVE-2026-62797
- CVE-2026-62800
- CVE-2026-62803
- CVE-2026-62807
- CVE-2026-62812
- CVE-2026-62814
- CVE-2026-62832
- CVE-2026-62876
- CVE-2026-62877
- CVE-2026-62880
- CVE-2026-62881
- CVE-2026-62883
- CVE-2026-62885
- CVE-2026-62887
- CVE-2026-62888
- CVE-2026-62892
- CVE-2026-62894
- CVE-2026-62908
- CVE-2026-62910
- CVE-2026-62912
- CVE-2026-62913
- CVE-2026-62914
- CVE-2026-62915
- CVE-2026-65662
- CVE-2026-65671
- CVE-2026-65678
- CVE-2026-65773
- CVE-2026-65774
- CVE-2026-65775
- CVE-2026-65784
- CVE-2026-65786
- CVE-2026-65787
- CVE-2026-65790
- CVE-2026-65794
- CVE-2026-65795
- CVE-2026-65797
- CVE-2026-65798
- CVE-2026-65799
- CVE-2026-65813
- CVE-2026-65814
- CVE-2026-66804
- CVE-2026-6726
- CVE-2026-6727
- CVE-2026-68819
- CVE-2026-68820
- CVE-2026-70304
- CVE-2026-70307
- CVE-2026-70330
- CVE-2026-70344
- CVE-2026-70345
- CVE-2026-70346
- CVE-2026-70347
- CVE-2026-62816
- CVE-2026-62818
- CVE-2026-62819
- CVE-2026-62822
- CVE-2026-62823
- CVE-2026-62824
- CVE-2026-62878
- CVE-2026-62889
- CVE-2026-62890
- CVE-2026-62893
- CVE-2026-62911
- CVE-2026-65791
- CVE-2026-66799
- CVE-2026-65679
- CVE-2026-65796
- CVE-2026-62727
Exploitation
Public exploits exist for this vulnerability.
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
- Microsoft-Windows
- Microsoft-Windows-Server
- Microsoft-Windows-Server-2012
- Microsoft-Exchange-Server
- Microsoft-Windows-10
CVE list
- CVE-2026-6726 critical
- CVE-2026-6727 high
- CVE-2026-42976 critical
- CVE-2026-49179 critical
- CVE-2026-50472 high
- CVE-2026-54113 critical
- CVE-2026-54984 critical
- CVE-2026-56174 critical
- CVE-2026-59122 high
- CVE-2026-59125 high
- CVE-2026-59126 high
- CVE-2026-59127 critical
- CVE-2026-59128 high
- CVE-2026-59130 high
- CVE-2026-59131 high
- CVE-2026-59132 critical
- CVE-2026-59134 critical
- CVE-2026-59135 high
- CVE-2026-59136 high
- CVE-2026-59137 high
- CVE-2026-59138 high
- CVE-2026-61345 high
- CVE-2026-61346 high
- CVE-2026-61347 high
- CVE-2026-61348 high
- CVE-2026-61349 critical
- CVE-2026-61350 warning
- CVE-2026-61352 critical
- CVE-2026-61353 critical
- CVE-2026-61355 critical
- CVE-2026-61356 critical
- CVE-2026-61358 critical
- CVE-2026-61360 high
- CVE-2026-61363 critical
- CVE-2026-61364 critical
- CVE-2026-61365 critical
- CVE-2026-61366 high
- CVE-2026-61367 critical
- CVE-2026-61368 high
- CVE-2026-61918 critical
- CVE-2026-61920 high
- CVE-2026-61921 high
- CVE-2026-61923 critical
- CVE-2026-61924 critical
- CVE-2026-61925 critical
- CVE-2026-61926 critical
- CVE-2026-61928 high
- CVE-2026-61930 critical
- CVE-2026-61932 critical
- CVE-2026-61936 high
- CVE-2026-61937 critical
- CVE-2026-61939 high
- CVE-2026-62690 high
- CVE-2026-62692 critical
- CVE-2026-62696 critical
- CVE-2026-62698 critical
- CVE-2026-62699 high
- CVE-2026-62700 critical
- CVE-2026-62701 critical
- CVE-2026-62702 critical
- CVE-2026-62703 high
- CVE-2026-62707 critical
- CVE-2026-62709 high
- CVE-2026-62710 critical
- CVE-2026-62711 critical
- CVE-2026-62712 critical
- CVE-2026-62713 critical
- CVE-2026-62714 high
- CVE-2026-62715 high
- CVE-2026-62716 high
- CVE-2026-62717 critical
- CVE-2026-62718 high
- CVE-2026-62719 critical
- CVE-2026-62720 high
- CVE-2026-62721 critical
- CVE-2026-62723 high
- CVE-2026-62724 high
- CVE-2026-62725 high
- CVE-2026-62726 high
- CVE-2026-62728 high
- CVE-2026-62729 high
- CVE-2026-62730 high
- CVE-2026-62732 critical
- CVE-2026-62733 critical
- CVE-2026-62734 high
- CVE-2026-62735 critical
- CVE-2026-62738 high
- CVE-2026-62739 critical
- CVE-2026-62740 high
- CVE-2026-62741 critical
- CVE-2026-62742 high
- CVE-2026-62743 high
- CVE-2026-62745 high
- CVE-2026-62746 high
- CVE-2026-62747 critical
- CVE-2026-62748 high
- CVE-2026-62750 high
- CVE-2026-62751 critical
- CVE-2026-62752 critical
- CVE-2026-62753 high
- CVE-2026-62754 critical
- CVE-2026-62755 critical
- CVE-2026-62757 high
- CVE-2026-62758 critical
- CVE-2026-62761 critical
- CVE-2026-62768 critical
- CVE-2026-62769 high
- CVE-2026-62770 critical
- CVE-2026-62771 critical
- CVE-2026-62773 high
- CVE-2026-62774 high
- CVE-2026-62776 critical
- CVE-2026-62777 critical
- CVE-2026-62778 critical
- CVE-2026-62781 critical
- CVE-2026-62782 critical
- CVE-2026-62783 critical
- CVE-2026-62784 critical
- CVE-2026-62785 critical
- CVE-2026-62786 high
- CVE-2026-62787 critical
- CVE-2026-62790 critical
- CVE-2026-62792 critical
- CVE-2026-62793 high
- CVE-2026-62795 critical
- CVE-2026-62796 high
- CVE-2026-62797 critical
- CVE-2026-62800 critical
- CVE-2026-62803 critical
- CVE-2026-62807 critical
- CVE-2026-62812 critical
- CVE-2026-62814 high
- CVE-2026-62816 critical
- CVE-2026-62818 critical
- CVE-2026-62819 critical
- CVE-2026-62822 critical
- CVE-2026-62823 critical
- CVE-2026-62824 critical
- CVE-2026-62832 critical
- CVE-2026-62876 critical
- CVE-2026-62877 critical
- CVE-2026-62878 critical
- CVE-2026-62880 critical
- CVE-2026-62881 high
- CVE-2026-62883 high
- CVE-2026-62885 critical
- CVE-2026-62887 high
- CVE-2026-62888 critical
- CVE-2026-62889 critical
- CVE-2026-62890 critical
- CVE-2026-62892 high
- CVE-2026-62893 critical
- CVE-2026-62894 critical
- CVE-2026-62908 high
- CVE-2026-62910 critical
- CVE-2026-62911 critical
- CVE-2026-62912 high
- CVE-2026-62913 critical
- CVE-2026-62914 high
- CVE-2026-62915 high
- CVE-2026-65662 high
- CVE-2026-65671 critical
- CVE-2026-65678 high
- CVE-2026-65679 critical
- CVE-2026-65773 critical
- CVE-2026-65774 critical
- CVE-2026-65775 critical
- CVE-2026-65784 high
- CVE-2026-65786 critical
- CVE-2026-65787 critical
- CVE-2026-65790 critical
- CVE-2026-65791 critical
- CVE-2026-65794 high
- CVE-2026-65795 high
- CVE-2026-65796 critical
- CVE-2026-65797 high
- CVE-2026-65798 high
- CVE-2026-65799 critical
- CVE-2026-65813 critical
- CVE-2026-65814 critical
- CVE-2026-66799 critical
- CVE-2026-66804 critical
- CVE-2026-68819 critical
- CVE-2026-68820 high
- CVE-2026-70304 critical
- CVE-2026-70307 high
- CVE-2026-70330 critical
- CVE-2026-70344 critical
- CVE-2026-70345 critical
- CVE-2026-70346 critical
- CVE-2026-70347 critical
- CVE-2026-62727 unknown
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!