CVE-2026-32157
- EPSS 0.13%
- Veröffentlicht 14.04.2026 16:57:26
- Zuletzt bearbeitet 07.05.2026 19:57:08
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-32154
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:25
- Zuletzt bearbeitet 17.04.2026 15:10:35
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-32156
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:25
- Zuletzt bearbeitet 23.04.2026 14:51:17
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
- EPSS 0.06%
- Veröffentlicht 14.04.2026 16:57:24
- Zuletzt bearbeitet 20.04.2026 18:27:30
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-32089
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:23
- Zuletzt bearbeitet 21.04.2026 15:04:29
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:23
- Zuletzt bearbeitet 21.04.2026 14:54:28
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:22
- Zuletzt bearbeitet 21.04.2026 15:09:42
Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:21
- Zuletzt bearbeitet 21.04.2026 20:49:46
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2026-32085
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:21
- Zuletzt bearbeitet 21.04.2026 20:46:58
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
- EPSS 0.05%
- Veröffentlicht 14.04.2026 16:57:20
- Zuletzt bearbeitet 21.04.2026 20:50:56
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.