CVE-2026-50318
- EPSS 0.26%
- Veröffentlicht 14.07.2026 17:06:07
- Zuletzt bearbeitet 16.07.2026 14:38:26
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-50351
- EPSS 2.8%
- Veröffentlicht 14.07.2026 17:06:07
- Zuletzt bearbeitet 23.07.2026 05:16:34
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
- EPSS 0.15%
- Veröffentlicht 14.07.2026 17:06:06
- Zuletzt bearbeitet 22.07.2026 16:17:34
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
- EPSS 0.21%
- Veröffentlicht 14.07.2026 17:06:06
- Zuletzt bearbeitet 22.07.2026 16:17:39
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
- EPSS 3.3%
- Veröffentlicht 14.07.2026 17:06:05
- Zuletzt bearbeitet 22.07.2026 16:17:34
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
- EPSS 0.15%
- Veröffentlicht 14.07.2026 17:06:05
- Zuletzt bearbeitet 22.07.2026 16:17:35
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-49801
- EPSS 0.3%
- Veröffentlicht 14.07.2026 17:06:04
- Zuletzt bearbeitet 22.07.2026 16:17:34
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- EPSS 0.15%
- Veröffentlicht 14.07.2026 17:06:04
- Zuletzt bearbeitet 22.07.2026 16:17:34
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50333
- EPSS 0.21%
- Veröffentlicht 14.07.2026 17:06:03
- Zuletzt bearbeitet 23.07.2026 05:16:33
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-50294
- EPSS 0.37%
- Veröffentlicht 14.07.2026 17:06:02
- Zuletzt bearbeitet 22.07.2026 16:17:35
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.