CVE-2026-70564
- EPSS 0.32%
- Veröffentlicht 08.09.2026 17:12:21
- Zuletzt bearbeitet 24.09.2026 23:18:40
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-70582
- EPSS 0.22%
- Veröffentlicht 08.09.2026 17:12:21
- Zuletzt bearbeitet 28.09.2026 20:20:35
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
- EPSS 0.25%
- Veröffentlicht 08.09.2026 17:12:20
- Zuletzt bearbeitet 24.09.2026 23:18:39
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
CVE-2026-70563
- EPSS 0.87%
- Veröffentlicht 08.09.2026 17:12:20
- Zuletzt bearbeitet 24.09.2026 23:18:39
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-70342
- EPSS 0.87%
- Veröffentlicht 08.09.2026 17:12:18
- Zuletzt bearbeitet 24.09.2026 23:18:39
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70289
- EPSS 0.35%
- Veröffentlicht 08.09.2026 17:12:17
- Zuletzt bearbeitet 24.09.2026 23:18:38
Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2026-69676
- EPSS 1.17%
- Veröffentlicht 08.09.2026 17:12:14
- Zuletzt bearbeitet 24.09.2026 23:18:18
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.
CVE-2026-69712
- EPSS 0.89%
- Veröffentlicht 08.09.2026 17:12:14
- Zuletzt bearbeitet 24.09.2026 23:18:21
Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.
CVE-2026-69730
- EPSS 1.05%
- Veröffentlicht 08.09.2026 17:12:13
- Zuletzt bearbeitet 24.09.2026 23:18:23
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-69770
- EPSS 0.4%
- Veröffentlicht 08.09.2026 17:12:12
- Zuletzt bearbeitet 24.09.2026 23:18:25
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.