CVE-2026-77492 Windows Storage Port Driver Information Disclosure Vulnerability
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Raw Image Extension allows an unauthorized attacker to execute code over a network.
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.