CVE-2026-62713 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-62713 US
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-62713 US
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62707 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62705 US
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-62703 US
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.
EPSS 0.00 CVE-2026-62699 US
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.8 CVE-2026-62702 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62693 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62690 US
Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61939 US
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-61936 US
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61934 US
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-61933 US
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61932 US
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62692 US
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61937 US
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-61930 US
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-61928 US
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61927 US
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61925 US
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-61924 US
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-61368 US
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61366 US
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61923 US
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61367 US
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61356 US
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
EPSS 0.00 CVE-2026-61350 US
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-61348 US
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-61361 US
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-61353 US
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-61345 Microsoft US
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-59138 Microsoft US
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-59137 US
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-59136 Microsoft US
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-59134 US
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-59135 Microsoft US
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
EPSS 0.02 CVSS 7.5 CVE-2026-59132 US
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-59130 AMD US
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-59133 Microsoft US
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-59128 US
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-59127 US
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47285 US
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47299 US
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-59113 US
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-49179 US
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
EPSS 0.01 CVSS 7.8 CVE-2026-54984 Microsoft US 2 zdrojů
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-54113 US
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-40375 Microsoft US
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-63516 Microsoft US
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-63512 Microsoft US
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.02 CVE-2026-63514 Microsoft US
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-62837 Microsoft US
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-62827 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-62829 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-57105 Microsoft US
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-58650 US
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-56174 US
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50472 US
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42976 US
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
EPSS 0.00 CVE-2026-70348 US
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68815 Microsoft US