CVE-2026-27925
- EPSS 0.08%
- Veröffentlicht 14.04.2026 16:58:13
- Zuletzt bearbeitet 22.04.2026 17:39:47
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-27923
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:58:12
- Zuletzt bearbeitet 22.04.2026 17:50:18
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:58:11
- Zuletzt bearbeitet 22.04.2026 17:51:21
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-27920
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:58:10
- Zuletzt bearbeitet 22.04.2026 17:53:14
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
CVE-2026-27914
- EPSS 0.07%
- Veröffentlicht 14.04.2026 16:58:09
- Zuletzt bearbeitet 22.04.2026 17:59:35
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
CVE-2026-27916
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:58:09
- Zuletzt bearbeitet 22.04.2026 17:57:21
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
CVE-2026-27911
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:58:06
- Zuletzt bearbeitet 23.04.2026 14:57:12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
CVE-2026-27909
- EPSS 0.08%
- Veröffentlicht 14.04.2026 16:58:05
- Zuletzt bearbeitet 23.04.2026 14:59:29
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-27910
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:58:05
- Zuletzt bearbeitet 23.04.2026 14:58:08
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-26184
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:58:04
- Zuletzt bearbeitet 23.04.2026 18:06:43
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.