Kaspersky ID:
KLA91207
Дата обнаружения:
11/08/2026
Обновлено:
03/09/2026

Описание

Multiple vulnerabilities were found in Microsoft Products (ESU). Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, gain privileges, obtain sensitive information, perform cross-site scripting attack, spoof user interface.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in Remote Access Management service/API (RPC server) can be exploited remotely to gain privileges.
  2. A remote code execution vulnerability in Windows Active Directory Domain Services can be exploited remotely to execute arbitrary code.
  3. An elevation of privilege vulnerability in Windows LUA File Virtualization Filter Driver can be exploited remotely to gain privileges.
  4. A denial of service vulnerability in Remote Procedure Call can be exploited remotely to cause denial of service.
  5. A remote code execution vulnerability in Windows Imaging Component can be exploited remotely to execute arbitrary code.
  6. An elevation of privilege vulnerability in Windows Narrator Braille can be exploited remotely to gain privileges.
  7. An elevation of privilege vulnerability in Windows Telephony Service can be exploited remotely to gain privileges.
  8. An elevation of privilege vulnerability in Windows Remote Desktop Services can be exploited remotely to gain privileges.
  9. An elevation of privilege vulnerability in Windows Event Logging Service can be exploited remotely to gain privileges.
  10. An elevation of privilege vulnerability in Windows Installer can be exploited remotely to gain privileges.
  11. An information disclosure vulnerability in Windows Encrypting File System (EFS) can be exploited remotely to obtain sensitive information.
  12. An information disclosure vulnerability in AMD Zen can be exploited remotely to obtain sensitive information.
  13. A denial of service vulnerability in Windows TCP/IP can be exploited remotely to cause denial of service.
  14. A remote code execution vulnerability in Remote Desktop Client can be exploited remotely to execute arbitrary code.
  15. An information disclosure vulnerability in Microsoft Windows Search Component can be exploited remotely to obtain sensitive information.
  16. An information disclosure vulnerability in Microsoft COM for Windows can be exploited remotely to obtain sensitive information.
  17. An information disclosure vulnerability in Windows Event Logging Service can be exploited remotely to obtain sensitive information.
  18. A denial of service vulnerability in Microsoft Remote Registry Service can be exploited remotely to cause denial of service.
  19. An elevation of privilege vulnerability in Windows Graphics Kernel can be exploited remotely to gain privileges.
  20. An elevation of privilege vulnerability in Windows Ancillary Function Driver for WinSock can be exploited remotely to gain privileges.
  21. An elevation of privilege vulnerability in Windows Work Folder Service can be exploited remotely to gain privileges.
  22. An information disclosure vulnerability in Windows NTFS can be exploited remotely to obtain sensitive information.
  23. An elevation of privilege vulnerability in Windows Sensor Data Service can be exploited remotely to gain privileges.
  24. An elevation of privilege vulnerability in Windows Accessibility Infrastructure (ATBroker.exe) can be exploited remotely to gain privileges.
  25. An information disclosure vulnerability in Windows GDI can be exploited remotely to obtain sensitive information.
  26. An elevation of privilege vulnerability in Windows Network Connection Broker can be exploited remotely to gain privileges.
  27. An information disclosure vulnerability in Windows Hyper-V can be exploited remotely to obtain sensitive information.
  28. An information disclosure vulnerability in Windows Remote Desktop Client can be exploited remotely to obtain sensitive information.
  29. A remote code execution vulnerability in Windows DNS Server can be exploited remotely to execute arbitrary code.
  30. An elevation of privilege vulnerability in Windows Display Enhancement Service can be exploited remotely to gain privileges.
  31. An elevation of privilege vulnerability in Windows USB Driver can be exploited remotely to gain privileges.
  32. A tampering vulnerability in Windows Hello can be exploited remotely to spoof user interface.
  33. An elevation of privilege vulnerability in Windows Kernel can be exploited remotely to gain privileges.
  34. An elevation of privilege vulnerability in Windows DWM Core Library can be exploited remotely to gain privileges.
  35. A security feature bypass vulnerability in Windows Defender Firewall Service can be exploited remotely to bypass security restrictions.
  36. An elevation of privilege vulnerability in Windows HTTP.sys can be exploited remotely to gain privileges.
  37. An elevation of privilege vulnerability in Winlogon can be exploited remotely to gain privileges.
  38. An elevation of privilege vulnerability in Windows Push Notifications can be exploited remotely to gain privileges.
  39. An elevation of privilege vulnerability in Windows Program Compatibility Assistant Service can be exploited remotely to gain privileges.
  40. An elevation of privilege vulnerability in Microsoft Digest Authentication can be exploited remotely to gain privileges.
  41. A remote code execution vulnerability in Windows Universal Disk Format File System Driver (UDFS) can be exploited remotely to execute arbitrary code.
  42. An elevation of privilege vulnerability in Windows NTFS can be exploited remotely to gain privileges.
  43. A denial of service vulnerability in Windows Graphics Kernel can be exploited remotely to cause denial of service.
  44. An information disclosure vulnerability in Windows DWM Core Library can be exploited remotely to obtain sensitive information.
  45. An elevation of privilege vulnerability in Windows Modern Device Management (MDM) can be exploited remotely to gain privileges.
  46. An information disclosure vulnerability in Windows GDI+ can be exploited remotely to obtain sensitive information.
  47. An elevation of privilege vulnerability in Windows Device Association Service can be exploited remotely to gain privileges.
  48. An elevation of privilege vulnerability in Windows Win32k can be exploited remotely to gain privileges.
  49. An elevation of privilege vulnerability in Windows Cloud Files Mini Filter Driver can be exploited remotely to gain privileges.
  50. An information disclosure vulnerability in Windows DHCP Server can be exploited remotely to obtain sensitive information.
  51. An elevation of privilege vulnerability in Windows Message Queuing can be exploited remotely to gain privileges.
  52. An elevation of privilege vulnerability in Windows User-Mode Power Service (UMPS) can be exploited remotely to gain privileges.
  53. An elevation of privilege vulnerability in Windows Common Log File System Driver can be exploited remotely to gain privileges.
  54. An information disclosure vulnerability in Windows Wired AutoConfig Service can be exploited remotely to obtain sensitive information.
  55. An information disclosure vulnerability in Windows Management Instrumentation can be exploited remotely to obtain sensitive information.
  56. An information disclosure vulnerability in Windows Imaging Component can be exploited remotely to obtain sensitive information.
  57. An information disclosure vulnerability in Win32k can be exploited remotely to obtain sensitive information.
  58. A tampering vulnerability in Windows HTTP Protocol Stack can be exploited remotely to spoof user interface.
  59. An elevation of privilege vulnerability in Windows Projected File System can be exploited remotely to gain privileges.
  60. An elevation of privilege vulnerability in Windows Kerberos can be exploited remotely to gain privileges.
  61. An elevation of privilege vulnerability in Windows DHCP Client can be exploited remotely to gain privileges.
  62. A security feature bypass vulnerability in Windows Schannel can be exploited remotely to bypass security restrictions.
  63. An elevation of privilege vulnerability in Windows Remote Access Connection Manager can be exploited remotely to gain privileges.
  64. An elevation of privilege vulnerability in Windows DHCP Server can be exploited remotely to gain privileges.
  65. An elevation of privilege vulnerability in Windows DNS can be exploited remotely to gain privileges.
  66. An elevation of privilege vulnerability in Windows Shell can be exploited remotely to gain privileges.
  67. An elevation of privilege vulnerability in Windows License Manager can be exploited remotely to gain privileges.
  68. A remote code execution vulnerability in RPC Runtime Library can be exploited remotely to execute arbitrary code.
  69. An information disclosure vulnerability in Windows SMB Client can be exploited remotely to obtain sensitive information.
  70. A remote code execution vulnerability in Microsoft Local Security Authority Server (lsasrv) can be exploited remotely to execute arbitrary code.
  71. A remote code execution vulnerability in Windows LDAP — Lightweight Directory Access Protocol can be exploited remotely to execute arbitrary code.
  72. A remote code execution vulnerability in Windows SMBv3 Server can be exploited remotely to execute arbitrary code.
  73. A remote code execution vulnerability in Windows TCP/IP can be exploited remotely to execute arbitrary code.
  74. A remote code execution vulnerability in Windows Reliable Multicast Transport Driver (RMCAST) can be exploited remotely to execute arbitrary code.
  75. A remote code execution vulnerability in Windows Active Directory Certificate Services (AD CS) can be exploited remotely to execute arbitrary code.
  76. A remote code execution vulnerability in Windows Routing and Remote Access Service (RRAS) can be exploited remotely to execute arbitrary code.
  77. A remote code execution vulnerability in Windows GDI+ can be exploited remotely to execute arbitrary code.
  78. A remote code execution vulnerability in Windows DHCP Server can be exploited remotely to execute arbitrary code.
  79. An elevation of privilege vulnerability in Windows User Profile Service can be exploited remotely to gain privileges.
  80. A remote code execution vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) can be exploited remotely to execute arbitrary code.
  81. An elevation of privilege vulnerability in Windows GDI+ can be exploited remotely to execute arbitrary code.
  82. An elevation of privilege vulnerability in Capability Access Management Service (camsvc) can be exploited remotely to gain privileges.
  83. A remote code execution vulnerability in Windows Deployment Services TFTP Server can be exploited remotely to execute arbitrary code.
  84. An elevation of privilege vulnerability in Windows Backup Engine can be exploited remotely to gain privileges.
  85. An elevation of privilege vulnerability in Microsoft Exchange Server can be exploited remotely to gain privileges.
  86. A denial of service vulnerability in Microsoft Exchange Server can be exploited remotely to cause denial of service.
  87. A remote code execution vulnerability in Microsoft Exchange Server can be exploited remotely to execute arbitrary code.
  88. A spoofing vulnerability in Microsoft Exchange Server can be exploited remotely to spoof user interface.
  89. A security feature bypass vulnerability in Microsoft Exchange Server can be exploited remotely to bypass security restrictions.
  90. An elevation of privilege vulnerability in Remote Access API can be exploited remotely to gain privileges.
  91. A remote code execution vulnerability in Windows iSCSI Target Service can be exploited remotely to execute arbitrary code.
  92. An elevation of privilege vulnerability in Desktop Window Manager can be exploited remotely to gain privileges.
  93. A denial of service vulnerability in Windows iSCSI Target Service can be exploited remotely to cause denial of service.
  94. An elevation of privilege vulnerability in Microsoft Windows Storage Port Driver can be exploited remotely to gain privileges.
  95. An elevation of privilege vulnerability in Windows Key Guard can be exploited remotely to gain privileges.
  96. An elevation of privilege vulnerability in Microsoft Windows Cross Device Service can be exploited remotely to gain privileges.
  97. Security UI vulnerability can be exploited to spoof user interface.
  98. A denial of service vulnerability in Windows Network File System can be exploited remotely to cause denial of service.

Первичный источник обнаружения

Эксплуатация

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Связанные продукты

Список CVE

  • CVE-2026-6726
    critical
  • CVE-2026-6727
    high
  • CVE-2026-42976
    critical
  • CVE-2026-49179
    critical
  • CVE-2026-50472
    high
  • CVE-2026-54113
    critical
  • CVE-2026-54984
    critical
  • CVE-2026-56174
    critical
  • CVE-2026-59122
    high
  • CVE-2026-59125
    high
  • CVE-2026-59126
    high
  • CVE-2026-59127
    critical
  • CVE-2026-59128
    high
  • CVE-2026-59130
    high
  • CVE-2026-59131
    high
  • CVE-2026-59132
    critical
  • CVE-2026-59134
    critical
  • CVE-2026-59135
    high
  • CVE-2026-59136
    high
  • CVE-2026-59137
    high
  • CVE-2026-59138
    high
  • CVE-2026-61345
    high
  • CVE-2026-61346
    high
  • CVE-2026-61347
    high
  • CVE-2026-61348
    high
  • CVE-2026-61349
    critical
  • CVE-2026-61350
    warning
  • CVE-2026-61352
    critical
  • CVE-2026-61353
    critical
  • CVE-2026-61355
    critical
  • CVE-2026-61356
    critical
  • CVE-2026-61358
    critical
  • CVE-2026-61360
    high
  • CVE-2026-61363
    critical
  • CVE-2026-61364
    critical
  • CVE-2026-61365
    critical
  • CVE-2026-61366
    high
  • CVE-2026-61367
    critical
  • CVE-2026-61368
    high
  • CVE-2026-61918
    critical
  • CVE-2026-61920
    high
  • CVE-2026-61921
    high
  • CVE-2026-61923
    critical
  • CVE-2026-61924
    critical
  • CVE-2026-61925
    critical
  • CVE-2026-61926
    critical
  • CVE-2026-61928
    high
  • CVE-2026-61930
    critical
  • CVE-2026-61932
    critical
  • CVE-2026-61936
    high
  • CVE-2026-61937
    critical
  • CVE-2026-61939
    high
  • CVE-2026-62690
    high
  • CVE-2026-62692
    critical
  • CVE-2026-62696
    critical
  • CVE-2026-62698
    critical
  • CVE-2026-62699
    high
  • CVE-2026-62700
    critical
  • CVE-2026-62701
    critical
  • CVE-2026-62702
    critical
  • CVE-2026-62703
    high
  • CVE-2026-62707
    critical
  • CVE-2026-62709
    high
  • CVE-2026-62710
    critical
  • CVE-2026-62711
    critical
  • CVE-2026-62712
    critical
  • CVE-2026-62713
    critical
  • CVE-2026-62714
    high
  • CVE-2026-62715
    high
  • CVE-2026-62716
    high
  • CVE-2026-62717
    critical
  • CVE-2026-62718
    high
  • CVE-2026-62719
    critical
  • CVE-2026-62720
    high
  • CVE-2026-62721
    critical
  • CVE-2026-62723
    high
  • CVE-2026-62724
    high
  • CVE-2026-62725
    high
  • CVE-2026-62726
    high
  • CVE-2026-62728
    high
  • CVE-2026-62729
    high
  • CVE-2026-62730
    high
  • CVE-2026-62732
    critical
  • CVE-2026-62733
    critical
  • CVE-2026-62734
    high
  • CVE-2026-62735
    critical
  • CVE-2026-62738
    high
  • CVE-2026-62739
    critical
  • CVE-2026-62740
    high
  • CVE-2026-62741
    critical
  • CVE-2026-62742
    high
  • CVE-2026-62743
    high
  • CVE-2026-62745
    high
  • CVE-2026-62746
    high
  • CVE-2026-62747
    critical
  • CVE-2026-62748
    high
  • CVE-2026-62750
    high
  • CVE-2026-62751
    critical
  • CVE-2026-62752
    critical
  • CVE-2026-62753
    high
  • CVE-2026-62754
    critical
  • CVE-2026-62755
    critical
  • CVE-2026-62757
    high
  • CVE-2026-62758
    critical
  • CVE-2026-62761
    critical
  • CVE-2026-62768
    critical
  • CVE-2026-62769
    high
  • CVE-2026-62770
    critical
  • CVE-2026-62771
    critical
  • CVE-2026-62773
    high
  • CVE-2026-62774
    high
  • CVE-2026-62776
    critical
  • CVE-2026-62777
    critical
  • CVE-2026-62778
    critical
  • CVE-2026-62781
    critical
  • CVE-2026-62782
    critical
  • CVE-2026-62783
    critical
  • CVE-2026-62784
    critical
  • CVE-2026-62785
    critical
  • CVE-2026-62786
    high
  • CVE-2026-62787
    critical
  • CVE-2026-62790
    critical
  • CVE-2026-62792
    critical
  • CVE-2026-62793
    high
  • CVE-2026-62795
    critical
  • CVE-2026-62796
    high
  • CVE-2026-62797
    critical
  • CVE-2026-62800
    critical
  • CVE-2026-62803
    critical
  • CVE-2026-62807
    critical
  • CVE-2026-62812
    critical
  • CVE-2026-62814
    high
  • CVE-2026-62816
    critical
  • CVE-2026-62818
    critical
  • CVE-2026-62819
    critical
  • CVE-2026-62822
    critical
  • CVE-2026-62823
    critical
  • CVE-2026-62824
    critical
  • CVE-2026-62832
    critical
  • CVE-2026-62876
    critical
  • CVE-2026-62877
    critical
  • CVE-2026-62878
    critical
  • CVE-2026-62880
    critical
  • CVE-2026-62881
    high
  • CVE-2026-62883
    high
  • CVE-2026-62885
    critical
  • CVE-2026-62887
    high
  • CVE-2026-62888
    critical
  • CVE-2026-62889
    critical
  • CVE-2026-62890
    critical
  • CVE-2026-62892
    high
  • CVE-2026-62893
    critical
  • CVE-2026-62894
    critical
  • CVE-2026-62908
    high
  • CVE-2026-62910
    critical
  • CVE-2026-62911
    critical
  • CVE-2026-62912
    high
  • CVE-2026-62913
    critical
  • CVE-2026-62914
    high
  • CVE-2026-62915
    high
  • CVE-2026-65662
    high
  • CVE-2026-65671
    critical
  • CVE-2026-65678
    high
  • CVE-2026-65679
    critical
  • CVE-2026-65773
    critical
  • CVE-2026-65774
    critical
  • CVE-2026-65775
    critical
  • CVE-2026-65784
    high
  • CVE-2026-65786
    critical
  • CVE-2026-65787
    critical
  • CVE-2026-65790
    critical
  • CVE-2026-65791
    critical
  • CVE-2026-65794
    high
  • CVE-2026-65795
    high
  • CVE-2026-65796
    critical
  • CVE-2026-65797
    high
  • CVE-2026-65798
    high
  • CVE-2026-65799
    critical
  • CVE-2026-65813
    critical
  • CVE-2026-65814
    critical
  • CVE-2026-66799
    critical
  • CVE-2026-66804
    critical
  • CVE-2026-68819
    critical
  • CVE-2026-68820
    high
  • CVE-2026-70304
    critical
  • CVE-2026-70307
    high
  • CVE-2026-70330
    critical
  • CVE-2026-70344
    critical
  • CVE-2026-70345
    critical
  • CVE-2026-70346
    critical
  • CVE-2026-70347
    critical
  • CVE-2026-62727
    unknown

Список KB

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Do you want to save your changes?
Your message has been sent successfully.