CVE-2026-71338 Windows Failover Cluster Elevation of Privilege Vulnerability
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71338 US
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71338 US
Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71334 US
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71332 US
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71337 US
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-71333 US
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-71330 US
Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-71336 US
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
EPSS 0.00 CVE-2026-71329 US
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-70587 US
Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-70586 US
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-70585 US
Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-70584 US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-70582 US
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-70564 US
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-70563 US
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-70562 US
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-70351 Microsoft US
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-58600 Microsoft US
Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-70342 US
Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-70289 US
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-70334 US
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-66305 US
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-63523 US
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69890 US
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69740 US
Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69676 US
Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69712 US
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69730 US
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69860 US
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69770 US
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69732 US
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69822 US
Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-69771 US
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69758 US
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69775 US
Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69772 US
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-69839 US
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69808 US
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69838 US
Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69691 US
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69832 US
Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69862 US
Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-69744 US
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69819 US
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69762 US
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69741 US
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69735 US
Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69896 US
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69681 US
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69757 US
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69889 US
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69723 US
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69875 US
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-69694 US
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69711 US
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69717 US
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69729 US
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69693 US
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69859 US
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-69638 US