Microsoft

Windows 11 26h1

1532 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 08.09.2026 17:16:39
  • Zuletzt bearbeitet 16.09.2026 17:56:41

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 08.09.2026 17:16:39
  • Zuletzt bearbeitet 16.09.2026 19:02:51

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 08.09.2026 17:16:38
  • Zuletzt bearbeitet 16.09.2026 21:25:31

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 08.09.2026 17:16:38
  • Zuletzt bearbeitet 16.09.2026 19:04:03

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 08.09.2026 17:16:37
  • Zuletzt bearbeitet 24.09.2026 23:18:26

Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 08.09.2026 17:16:36
  • Zuletzt bearbeitet 22.09.2026 19:11:11

Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.

Medienbericht
  • EPSS 0.52%
  • Veröffentlicht 08.09.2026 17:16:35
  • Zuletzt bearbeitet 24.09.2026 23:18:24

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 08.09.2026 17:16:35
  • Zuletzt bearbeitet 24.09.2026 23:18:33

Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.

Medienbericht
  • EPSS 0.2%
  • Veröffentlicht 08.09.2026 17:16:34
  • Zuletzt bearbeitet 22.09.2026 19:46:23

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.

Medienbericht
  • EPSS 1.1%
  • Veröffentlicht 08.09.2026 17:16:34
  • Zuletzt bearbeitet 24.09.2026 19:12:06

Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.