CVE-2026-49170
- EPSS 2.8%
- Veröffentlicht 14.07.2026 17:04:29
- Zuletzt bearbeitet 22.07.2026 16:17:27
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
CVE-2026-49166
- EPSS 0.24%
- Veröffentlicht 14.07.2026 17:04:27
- Zuletzt bearbeitet 22.07.2026 16:17:27
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-49165
- EPSS 0.24%
- Veröffentlicht 14.07.2026 17:04:26
- Zuletzt bearbeitet 29.07.2026 20:17:03
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
CVE-2026-34346
- EPSS 0.2%
- Veröffentlicht 14.07.2026 17:04:19
- Zuletzt bearbeitet 22.07.2026 16:17:17
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
CVE-2026-42982
- EPSS 0.27%
- Veröffentlicht 14.07.2026 17:04:14
- Zuletzt bearbeitet 22.07.2026 16:17:22
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-48583
- EPSS 0.27%
- Veröffentlicht 09.06.2026 17:17:46
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49160
- EPSS 53.83%
- Veröffentlicht 09.06.2026 17:17:46
- Zuletzt bearbeitet 23.07.2026 08:10:00
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
- EPSS 0.22%
- Veröffentlicht 09.06.2026 17:17:36
- Zuletzt bearbeitet 23.07.2026 08:10:00
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-45654
- EPSS 0.31%
- Veröffentlicht 09.06.2026 17:17:32
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-45642
- EPSS 0.32%
- Veröffentlicht 09.06.2026 17:17:31
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.