Zeros312
CVE-2026-33112 | msrc_CVE-2026-33112 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-27 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33112.json | ['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280'] | 3c220758b22d143d0a581ddb987f872add6097949f7e3b5e1a27ab76e11ace5a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33112', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.246Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-27T07:00:00.000Z', 'number': '2', 'summary': 'Acknowledgement added. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-27T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33112', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33112.json', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/_l0gg">khoadha</a>']}, {'names': ['<a href="https://www.linkedin.com/in/rafaellresende/">Rafael Resende</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33112', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33112', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33112.json', 'summary': 'CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]} |
CVE-2026-45498 | msrc_CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | Low | 2026-05-12 10:00:00+03:00 | 2026-05-26 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45498.json | ['Microsoft Defender Antimalware Platform 4.18.26040.7', 'Microsoft Defender Antimalware Platform <4.18.26040.7'] | 04c893085c117737faeecfc21d88760c6d89997fc9299582163cd2a4d3efaa1b | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Defender Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45498', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.234Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'CWE added. Informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45498.json', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Low', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Defender Antimalware Platform', 'branches': [{'name': '<4.18.26040.7', 'product': {'name': 'Microsoft Defender Antimalware Platform <4.18.26040.7', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '4.18.26040.7', 'product': {'name': 'Microsoft Defender Antimalware Platform 4.18.26040.7', 'product_id': '11744'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45498', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Last version of the Microsoft Defender Antimalware Platform affected by this vulnerability: Last version of the Microsoft Defender Antimalware Platform affected by this vulnerability, 4.18.26030.3011: 4.18.26030.3011, First version of the Microsoft Defender Antimalware Platform with this vulnerability addressed: First version of the Microsoft Defender Antimalware Platform with this vulnerability addressed, Version 4.18.26040.7: Version 4.18.26040.7\nSee Manage Updates Baselines Microsoft Defender Antivirus for more information.\nVulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.\nIn response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Windows Defender Antimalware Platform. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner.\nFor enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Windows Defender Antimalware Platform are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.\nBest practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Windows Defender Antimalware Platform updates and malware definitions, is working as expected in their environment.\nMicrosoft typically releases an update for the Microsoft Defender Antimalware Platform once a month or as needed to protect against new threats. Microsoft also typically updates the malware definitions three times daily and can increase the frequency when needed.\nDepending on which Microsoft antimalware software is used and how it is configured, the software may search for platform, engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.\nThe Microsoft Defender Antimalware Platform is a collection of user-mode binaries (e.g. MsMpEng.exe) and kernel-mode drivers that run on top of Windows to keep devices protected against new and prevalent threats.\nDefender runs on all supported versions of Windows.\nYes, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.\nYes.\xa0 In addition to the changes that are listed for this vulnerability, this update includes defense-in-depth updates to help improve security-related features.\nCustomers should verify that the latest version of the Microsoft Malware Protection Platform and definition updates are being actively downloaded and installed for their Microsoft antimalware products.\nOpen the Windows Security program. For example, type Security in the Search bar, and select the Windows Security program.\nIn the navigation pane, select Virus & threat protection.\nThen click on Protection Updates in the Virus & threat protection section updates.\nSelect Check for updates.\nIn the navigation pane, select Settings, and then select About.\nExamine the Antimalware ClientVersion number. The update was successfully installed if the Malware Protection Platform version number or the signature package version number matches or exceeds the version number that you are trying to verify as installed.', 'title': 'Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?', 'category': 'faq'}], 'title': 'Microsoft Defender Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.0, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C', 'temporalScore': 3.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45498.json', 'summary': 'CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://www.microsoft.com/en-us/wdsi/defenderupdates', 'date': '2026-05-19T07:00:00.000Z', 'details': '4.18.26040.7:Security Update:https://www.microsoft.com/en-us/wdsi/defenderupdates', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11744'], 'known_affected': ['1']}}]} |
CVE-2026-41091 | msrc_CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-26 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41091.json | ['Microsoft Malware Protection Engine 1.1.26040.8', 'Microsoft Malware Protection Engine <1.1.26040.8'] | bdb1e19819871d645b80ba9a08b833a1197b5dc67f0dad06ace59199b1013f2a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Defender Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41091', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.235Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'In the Security Updates table, added links to the Release Notes. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41091.json', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://github.com/void2012 "> Damir Moldovanov </a>']}, {'names': ['<a href="https://www.linkedin.com/in/andrewcdorman">ACD421</a> with Hollow Point Labs']}, {'names': ['<a href="https://www.linkedin.com/in/andrewcdorman">ACD421</a> with Hollow Point Labs']}, {'names': ['Anonymous']}, {'names': ['Diffract']}, {'names': ['<a href="https://x.com/sibusisosishi">Sibusiso</a> with <a href="https://www.ironsky.co.za/">Ironsky</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Malware Protection Engine', 'branches': [{'name': '<1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine <1.1.26040.8', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine 1.1.26040.8', 'product_id': '11902'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41091', 'cwe': {'id': 'CWE-59', 'name': "Improper Link Resolution Before File Access ('Link Following')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}, {'text': 'Last version of the Microsoft Malware Protection Engine affected by this vulnerability: Last version of the Microsoft Malware Protection Engine affected by this vulnerability, 1.1.26030.3008: 1.1.26030.3008, First version of the Microsoft Malware Protection Engine with this vulnerability addressed: First version of the Microsoft Malware Protection Engine with this vulnerability addressed, Version 1.1.26040.8: Version 1.1.26040.8\nSee Manage Updates Baselines Microsoft Defender Antivirus for more information.\nVulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.\nIn response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner.\nFor enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.\nBest practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Microsoft Malware Protection Engine updates and malware definitions, is working as expected in their environment.\nMicrosoft typically releases an update for the Microsoft Malware Protection Engine once a month or as needed to protect against new threats. Microsoft also typically updates the malware definitions three times daily and can increase the frequency when needed.\nDepending on which Microsoft antimalware software is used and how it is configured, the software may search for engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.\nThe Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.\nDefender runs on all supported version of Windows.\nYes, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.\nYes.\xa0 In addition to the changes that are listed for this vulnerability, this update includes defense-in-depth updates to help improve security-related features.', 'title': 'Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?', 'category': 'faq'}], 'title': 'Microsoft Defender Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41091.json', 'summary': 'CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'date': '2026-05-19T07:00:00.000Z', 'details': '1.1.26040.8:Security Update:https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11902'], 'known_affected': ['1']}}]} |
CVE-2026-45584 | msrc_CVE-2026-45584 | Microsoft Defender Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-26 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45584.json | ['Microsoft Malware Protection Engine 1.1.26040.8', 'Microsoft Malware Protection Engine <1.1.26040.8'] | 99e8c01dfed2ed0173baaca48ea94238d00b7e3713ae10dfa838a30508ffdb68 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Defender Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45584', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.348Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'In the Security Updates table, added links to the Release Notes. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45584.json', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://dawnslab.jd.com/">haowei yan(jingdong dawnslab)</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Malware Protection Engine', 'branches': [{'name': '<1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine <1.1.26040.8', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.1.26040.8', 'product': {'name': 'Microsoft Malware Protection Engine 1.1.26040.8', 'product_id': '11902'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45584', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'Successful exploitation of this vulnerability would require a remote, unauthenticated attacker to entice a local user to take multiple actions that results in Defender scanning a malicious file that has been quarantined.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'Last version of the Microsoft Malware Protection Engine affected by this vulnerability: Last version of the Microsoft Malware Protection Engine affected by this vulnerability, 1.1.26030.3008: 1.1.26030.3008, First version of the Microsoft Malware Protection Engine with this vulnerability addressed: First version of the Microsoft Malware Protection Engine with this vulnerability addressed, Version 1.1.26040.8: Version 1.1.26040.8\nSee Manage Updates Baselines Microsoft Defender Antivirus for more information.\nVulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.\nIn response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine. In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner.\nFor enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating.\nBest practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Microsoft Malware Protection Engine updates and malware definitions, is working as expected in their environment.\nMicrosoft typically releases an update for the Microsoft Malware Protection Engine once a month or as needed to protect against new threats. Microsoft also typically updates the malware definitions three times daily and can increase the frequency when needed.\nDepending on which Microsoft antimalware software is used and how it is configured, the software may search for engine and definition updates every day when connected to the Internet, up to multiple times daily. Customers can also choose to manually check for updates at any time.\nThe Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.\nDefender runs on all supported version of Windows.\nYes, Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.\nYes.\xa0 In addition to the changes that are listed for this vulnerability, this update includes defense-in-depth updates to help improve security-related features.', 'title': 'Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?', 'category': 'faq'}], 'title': 'Microsoft Defender Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45584.json', 'summary': 'CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'date': '2026-05-19T07:00:00.000Z', 'details': '1.1.26040.8:Security Update:https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11902'], 'known_affected': ['1']}}]} |
CVE-2026-45659 | msrc_CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-26 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45659.json | ['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280'] | 73e021248118abb837d7a82d4b7b5777940786a270a672d57cae8626e7d27d04 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45659', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.350Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-26T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45659.json', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['MEOW']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45659', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}, {'text': 'The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45659.json', 'summary': 'CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-21T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-21T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-21T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]} |
CVE-2026-34336 | msrc_CVE-2026-34336 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-22 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34336.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 3bb5df5ccce0f6b9816a9fed159c0eb87ef8fbd71e3f7b348f40983b9ff6a781 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34336', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.276Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-22T07:00:00.000Z', 'number': '2', 'summary': 'The security impact for this CVE has been revised based on a re-assessment of the vulnerability. The original classification of Information Disclosure (ID) has been updated to Elevation of Privilege (EoP).', 'legacy_version': '2'}], 'current_release_date': '2026-05-22T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34336', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34336.json', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/immortalp0ny">Sergey immortalp0ny Tarasov</a> with <a href="https://global.ptsecurity.com/">Positive Technologies</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34336', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34336', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34336.json', 'summary': 'CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}], 'product_status': {'fixed': ['10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}}]} |
CVE-2026-33117 | msrc_CVE-2026-33117 | Azure SDK for Java Security Feature Bypass Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-22 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33117.json | ['Azure SDK for Java 4.10.6', 'Azure SDK for Java <4.10.6'] | 309ff54297581c148954148791061fae17446c8f8226780ea233093e78aea007 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure SDK for Java Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33117', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:56.961Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-22T07:00:00.000Z', 'number': '2', 'summary': 'The executive summary has been updated to include additional details about this vulnerability. This change does not affect the available security updates. Customers should install the recommended updates to remain protected from this vulnerability.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-22T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33117.json', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['sho odagiri with <a href="https://gmo-cybersecurity.com/">GMO CyberSecurity by ierae inc</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure SDK for Java', 'branches': [{'name': '<4.10.6', 'product': {'name': 'Azure SDK for Java <4.10.6', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '4.10.6', 'product': {'name': 'Azure SDK for Java 4.10.6', 'product_id': '11817'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33117', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to bypass the integrity protection provided by the authentication tag that is designed to detect tampering with encrypted data. This may prevent the system from identifying whether encrypted content has been modified before it is decrypted.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by sending specially crafted encrypted data to an affected application that uses the vulnerable decryption implementation and observing how the application responds. If the application is reachable over a network, this could allow the attacker to manipulate encrypted input in a way that bypasses integrity checks during decryption.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure SDK for Java Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 7.9, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33117.json', 'summary': 'CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://github.com/Azure/azure-sdk-for-java/pull/48476', 'date': '2026-05-12T07:00:00.000Z', 'details': '4.10.6:Security Update:https://github.com/Azure/azure-sdk-for-java/pull/48476', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11817'], 'known_affected': ['1']}}]} |
CVE-2026-32185 | msrc_CVE-2026-32185 | Microsoft Teams Spoofing Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32185.json | ['Microsoft Teams for Android 1.0.0.2026092402', 'Microsoft Teams for Android <1.0.0.2026092402'] | ea4a754e8f5bca746c7ff12af112e910bc939866820a28ece196c35769462664 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Teams Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32185', 'status': 'final', 'version': '3', 'generator': {'date': '2026-05-28T01:40:57.208Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-18T07:00:00.000Z', 'number': '2', 'summary': 'The security update for Microsoft Teams for Android is not immediately available. Customers running affected Microsoft Teams for would need to install the update to be protected from this vulnerability, once the update becomes available.', 'legacy_version': '2'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '3', 'summary': 'Microsoft is announcing the availability of the security update for Microsoft Teams for Android. Customers running affected Microsoft Teams for Android should install the update for their product to be protected from this vulnerability.', 'legacy_version': '3'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32185.json', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Teams for Android', 'branches': [{'name': '<1.0.0.2026092402', 'product': {'name': 'Microsoft Teams for Android <1.0.0.2026092402', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.0.0.2026092402', 'product': {'name': 'Microsoft Teams for Android 1.0.0.2026092402', 'product_id': '12007'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32185', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. As of May 21, 2026, the security update for Microsoft Teams for Android is available. Customers running Microsoft Teams for Android should ensure the update is installed to be protected from this vulnerability.', 'title': 'Are the updates for Microsoft Teams for Android currently available?', 'category': 'faq'}], 'title': 'Microsoft Teams Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32185.json', 'summary': 'CVE-2026-32185 Microsoft Teams Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.microsoft.teams', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.0.0.2026092402:Security Update:https://play.google.com/store/apps/details?id=com.microsoft.teams', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12007'], 'known_affected': ['1']}}]} |
CVE-2026-40412 | msrc_CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40412.json | ['Azure Orbital Spatio'] | f5a3dada04fdef2acb2b973d56760f73a7c2763b83bfa42e2fc683968a68994d | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Orbital Spatio Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40412', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.934Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40412', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40412.json', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Michal Kamensky with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Orbital Spatio', 'product': {'name': 'Azure Orbital Spatio', 'product_id': '21320'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40412', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Orbital Spatio Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21320']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40412', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40412.json', 'summary': 'CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21320']}}]} |
CVE-2026-23652 | msrc_CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23652.json | ['Microsoft Power Pages'] | 4553dd5ee83b09954eee5a04020cb5c09ea90937a149c63377c21c74f30e9eec | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Power Pages Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-23652', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.935Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23652', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23652.json', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://nl.linkedin.com/in/erik-donker-50a887bb">Erik Donker</a> with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Power Pages', 'product': {'name': 'Microsoft Power Pages', 'product_id': '12497'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-23652', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Power Pages Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12497']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23652', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23652.json', 'summary': 'CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12497']}}]} |
CVE-2026-35430 | msrc_CVE-2026-35430 | Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35430.json | ['Azure Privileged Identity Management (PIM)'] | 058f48ec955f81db2d3f326401454c3f44cd8ba4d422a8ec62d544b46c0948f8 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35430', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.936Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35430', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35430.json', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Privileged Identity Management (PIM)', 'product': {'name': 'Azure Privileged Identity Management (PIM)', 'product_id': '21345'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35430', 'cwe': {'id': 'CWE-639', 'name': 'Authorization Bypass Through User-Controlled Key'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21345']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35430', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35430.json', 'summary': 'CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21345']}}]} |
CVE-2013-3900 | msrc_CVE-2013-3900 | WinVerifyTrust Signature Validation Vulnerability | Important | 2022-01-11 11:00:00+03:00 | 2024-12-23 11:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2013-3900.json | 8af2684fe6c042a0b7f7777a44c5dd913bcc0e097b9d47e7ee558e9a1c4510bf | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'WinVerifyTrust Signature Validation Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2013-3900', 'status': 'final', 'version': '6', 'generator': {'date': '2026-01-06T21:23:09.936Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2022-01-21T08:00:00.000Z', 'number': '1', 'summary': 'Information published in the Security Update Guide to update the Security Updates table and to inform customers that there are actions they need to take to protect their systems from this vulnerability. CVE-2013-3900 was originally published on December 10, 2013 on TechNet.', 'legacy_version': '1'}, {'date': '2023-04-11T07:00:00.000Z', 'number': '2', 'summary': 'In the Security Updates table, added the Server Core installation versions of the following versions of Windows as they are affected by the vulnerability: Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2, Windows Server 2008 R2 for x64-based Systems Service 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022. Customers running these Server Core installations should review the FAQs and Suggested Actions section of this CVE and take action as necessary.', 'legacy_version': '2'}, {'date': '2023-05-09T07:00:00.000Z', 'number': '3', 'summary': 'In the Executive Summary, corrected information about Windows 10 and Windows 11 to state that the supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. This is an informational change only.', 'legacy_version': '2.1'}, {'date': '2024-04-11T07:00:00.000Z', 'number': '4', 'summary': 'Updated FAQs to inform customers that EnableCertPaddingCheck is data type REG_SZ (a string value) and not data type dword. When you specify \'EnableCertPaddingCheck" as in "DataItemName1"="DataType1:DataValue1" do not include the date type value or colon. This is an informational change only.', 'legacy_version': '2.2'}, {'date': '2024-11-12T08:00:00.000Z', 'number': '5', 'summary': '**Corrected** Correcting the published information from the previous revision. EnableCertPaddingCheck is data type REG_DWORD (an integer value) and not data type string: "EnableCertPaddingCheck"=dword:1. The FAQ section has been updated accordingly. This is an informational change only.', 'legacy_version': '2.3'}, {'date': '2024-12-23T08:00:00.000Z', 'number': '6', 'summary': 'Providing further clarification about how to configure the EnableCertPaddingCheck registry value to implement and revert the improvement to authenticode signature verification. Customers who had successfully followed previous guidance do not need to make further changes to their systems. Although Windows treats the EnableCertPaddingCheck value as a DWORD, its actual registry value type does not matter, as long as all these length and data requirements are met. See the **Suggested Actions** section for more information.', 'legacy_version': '2.4'}], 'current_release_date': '2024-12-23T08:00:00.000Z', 'initial_release_date': '2022-01-11T08:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2013-3900.json', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'vulnerabilities': [{'cve': 'CVE-2013-3900', 'cwe': {'id': 'CWE-347', 'name': 'Improper Verification of Cryptographic Signature'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Opting into the stricter verification behavior causes the WinVerifyTrust function to perform strict Windows Authenticode signature verification for PE files. After you opt in, PE files will be considered "unsigned" if Windows identifies content in them that does not conform to the Authenticode specification. This may impact some installers. If you are using an installer that is impacted, Microsoft recommends using an installer that only extracts content from validated portions of the signed file.\nCustomers who would like to enable the new Authenticode signature verification behavior can do so by setting a key in the system registry. When the key is set, Windows Authenticode signature verification will no longer recognize binaries with Authenticode signatures that contain extraneous information in the WIN_CERTIFICATE structure. Customers can choose to disable the functionality at any time by disabling this registry key. See Suggested Actions for instructions.\nCustomers who have already enabled the stricter verification behavior, and have not experienced problems, can choose to leave the verification behavior enabled. Customers who are experiencing application compatibility problems with the new behavior, or customers who simply want to disable the new behavior, can disable the functionality by removing the EnableCertPaddingCheck registry key or by setting it to REG_DWORD value 0. See Suggested Actions for instructions.\nNo. The stricter verification behavior resides on the system but will be dormant functionality until enabled.\nThe new stricter verification behavior, when enabled, applies primarily to portable executable (PE) binaries that are signed with the Windows Authenticode signature format. Binaries that are not signed with this format or that do not use WinVerifyTrust to verify signatures are not affected by the new behavior. Binaries most likely to be affected are PE installer files distributed via the Internet that are customized at time of download. The most common scenario in which users could perceive an impact is during the downloading and installation of new applications. This is the case only if customers have chosen to enable the stricter verification behavior, after which users may observe warning messages when attempting to install new applications with signatures that fail validation.\nFor customers who have chosen to enable the stricter verification behavior, any AppLocker rule that depends on files being signed, or expects a specific publisher, may be impacted if the signature on a file does not meet the stricter Authenticode signature verification requirements.\nNo. The new verification behavior does not impact WDAC.\nFor customers who have chosen to enable the stricter verification behavior, any Software Restriction Policy that depends on files being signed, or expects a specific publisher, may be impacted if the signature on a file does not meet the stricter Authenticode signature verification requirements.\nIf a binary is deemed non-compliant with the stricter Authenticode signature verification behavior, this will not be a problem on systems that have not had the new verification behavior enabled because Microsoft is not enforcing the stricter behavior by default. However, to correct problems with a binary failing validation on systems where the new verification behavior has been enabled, that binary will need to be re-signed with strict adherence to the Windows Authenticode Signature format and specifically not include extraneous information in the WIN_CERTIFICATE structure.\nYes. For customers opting to enable the stricter verification behavior, signing binaries with non-Microsoft-provided signing tools runs the risk of signatures being recognized as non-compliant with the stricter verification behavior. Using Microsoft products, or signature tools Microsoft provides, such as signtool.exe, helps to ensure that signatures are recognized as compliant.\nWindows Authenticode is a digital signature format that is used to determine the origin and integrity of software binaries. Authenticode uses Public-Key Cryptography Standards (PKCS) #7 signed data and X.509 certificates to bind an Authenticode-signed binary to the identity of a software publisher. The term "Authenticode signature" refers to a digital signature format that is generated and verified using the WinVerifyTrust function.\nWindows Authenticode signature verification consists of two primary activities: signature checking on specified objects and trust verification. These activities are carried out by the WinVerifyTrust function, which executes a signature check then passes the inquiry to a trust provider that supports the action identifier, if one exists. For more technical information regarding the WinVerifyTrust function, see WinVerifyTrust function. For an introduction to Authenticode, see Introduction to Code Signing.\nCustomers who are interested in learning more about the topic covered in this advisory should review Windows Root Certificate Program - Technical Requirements.\nAfter reviewing the technical details underlying the change in Authenticode signature verification behavior, Microsoft recommends that customers ensure that their Authenticode signatures do not contain extraneous information in the WIN_CERTIFICATE structure. Microsoft also recommends that executables authors consider conforming their Authenticode-signed binaries to the new verification standard. Authors who have modified their binary signing processes and would like to enable the new behavior may do so on an opt-in basis. Windows Root Certificate Program - Technical Requirements for guidance.\nTo enable the Authenticode signature verification improvements, configure the EnableCertPaddingCheck registry value to a non-zero value. Two ways that you can do this are through Group Policy, or with a .reg (“Registration Entries”) file. Implementing the improvement through Group Policy is available via the “MS Security Guide” administrative template, downloadable with the most recent Windows security baseline in the Microsoft Security Compliance Toolkit. After the SecGuide.admx and SecGuide.adml files are copied into the administrative template store, enable the “Enable Certificate Padding” policy in Computer Configuration\\Administrative Templates\\MS Security Guide.\nTo implement the improvement with a .reg file, paste the following text into a text editor such as Notepad, save the file by using the .reg file name extension (for example, enableAuthenticodeVerification.reg). You can apply the .reg file to individual systems by double-clicking it. You can automate its application with the REG.EXE IMPORT command.\nFor 32-bit versions of Windows, use the following text:\nFor 64-bit versions of Windows, use this text:\nEarlier versions of CVE-2013-3900 had recommended configuring EnableCertPaddingCheck to string value “1”, rather than to DWORD 1. Customers who had followed that guidance do not need to make further changes to their systems. Although Windows treats the EnableCertPaddingCheck value as a DWORD, its actual registry value type does not matter, as long as all these length and data requirements are met:\nThe EnableCertPaddingCheck registry value is present (any data type), The value’s data length is from 1 to 4 bytes, At least one of those bytes is a non-zero value\nCompliance validation tools should not fail the EnableCertPaddingCheck inspection for its value type. Ideally, a test should read the value as a four-byte value, ignoring its type, and pass the test if the four-byte value is present and non-zero. If a scanning tool does not support specifying validation criteria that way, then given the two specific ways Microsoft has published to configure the setting, scanning tools should pass the check if either of these is true:\nEnableCertPaddingCheck is a REG_DWORD, value exactly "1", EnableCertPaddingCheck is a REG_SZ, value exactly "1"\nTo revert to Windows default behavior and disable the Authenticode signature verification improvements, delete the EnableCertPaddingCheck registry value or set it to a DWORD value 0. Two ways that you can do this are through Group Policy, or with a .reg (“Registration Entries”) file.\nTo revert the improvement through Group Policy, configure the “MS Security Guide” policy described in Implement the Improvement to Authenticode Signature Verification to "Disabled".\nTo revert the improvement with a .reg file, paste the following text into a text editor such as Notepad, save the file by using the .reg file name extension (for example, disableAuthenticodeVerification.reg). You can apply the .reg file to individual systems by double-clicking it. You can automate its application with the REG.EXE IMPORT command.\nFor 32-bit versions of Windows, use the following text:\nFor 64-bit versions of Windows, use the following text:', 'title': 'What is the result of opting into the stricter verification behavior?', 'category': 'faq'}], 'title': 'WinVerifyTrust Signature Validation Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31', '32', '33', '34', '35', '36', '37', '38', '39', '40']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation Detected', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2013-3900.json', 'summary': 'CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['9312', '9318', '9344', '10049', '10051', '10287', '10378', '10379', '10483', '10543', '10729', '10735', '10816', '10852', '10853', '10855', '11568', '11569', '11570', '11571', '11572', '11923', '11924', '11926', '11927', '11929', '11930', '11931', '12085', '12086', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31', '32', '33', '34', '35', '36', '37', '38', '39', '40']}}]} | |
CVE-2026-45585 | msrc_CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-06-09 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45585.json | ['Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8655', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8655', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8655', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8655', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2269', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2269', 'Windows Server 2025 (Server Core installation) 10.0.26100.32995', 'Windows Server 2025 (Server Core installation) <10.0.26100.32995', 'Windows Server 2025 10.0.26100.32995', 'Windows Server 2025 <10.0.26100.32995'] | 5217d69211ff3f901d5cf17d4538265fcf1090cb4da341cb422961f7bd4fba51 | 2026-05-29 20:36:27.484886+03:00 | 2026-06-10 15:29:50.715579+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows BitLocker Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45585', 'status': 'final', 'version': '7', 'generator': {'date': '2026-06-09T19:32:20.321Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-20T07:00:00.000Z', 'number': '2', 'summary': 'Updated **Step 2** of the first mitigation. This is an informational change only.', 'legacy_version': '1.1'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '3', 'summary': 'Added a script to implement a mitigation and removed the manual mitigations. Please read the information to decide if you need to run the provided script.', 'legacy_version': '1.2'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '4', 'summary': 'Fixed a typographical error. This is an information change only.', 'legacy_version': '1.3'}, {'date': '2026-05-21T07:00:00.000Z', 'number': '5', 'summary': 'Updated the script in the FAQ section to make it language agnostic. Microsoft recommends customers to recopy the script and then run it to enable the mitigation.', 'legacy_version': '1.4'}, {'date': '2026-06-09T07:00:00.000Z', 'number': '6', 'summary': 'Added links to June 2026 Windows security updates. Microsoft recommends installing this updates as soon as possible.', 'legacy_version': '2'}, {'date': '2026-06-09T07:00:00.000Z', 'number': '7', 'summary': 'Updated product information in the Software Update table. This is an informational change only.', 'legacy_version': '2.1'}], 'current_release_date': '2026-06-09T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45585.json', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32995', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32995', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32995', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32995', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8655', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8655', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8655', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8655', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8655', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8655', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8655', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8655', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32995', 'product': {'name': 'Windows Server 2025 <10.0.26100.32995', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32995', 'product': {'name': 'Windows Server 2025 10.0.26100.32995', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2269', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2269', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2269', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2269', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45585', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}, {'text': 'Yes. This script is an interim security fix that helps to reduce the risk of exploitation of the vulnerability.\nThe script is for WinRE and removes autofstx.exe from the BootExecute registry value. Since BootExecute runs programs very early in boot (even in recovery mode), removing this entry prevents that executable from running in a high‑privilege environment, reducing risk.\nIt works by mounting the WinRE image, editing its offline SYSTEM registry to remove the entry if present, then safely committing changes and re‑sealing WinRE so BitLocker trust remains intact.\nIt’s designed to be safe—if the autofstx.exe entry isn’t there, it exits without making changes.', 'title': 'Is there a script that I can copy and paste to implement a mitigation?', 'category': 'faq'}], 'title': 'Windows BitLocker Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.8, 'attackVector': 'PHYSICAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C', 'temporalScore': 6.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'WORKAROUND', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45585.json', 'summary': 'CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5094125', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.26100.32995:Security Update:https://support.microsoft.com/help/5094125', 'category': 'vendor_fix', 'product_ids': ['3', '4']}, {'url': 'https://support.microsoft.com/help/5094126', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.26200.8655:Security Update:https://support.microsoft.com/help/5094126', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5094126', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.26100.8655:Security Update:https://support.microsoft.com/help/5094126', 'category': 'vendor_fix', 'product_ids': ['5']}, {'url': 'https://support.microsoft.com/help/5095051', 'date': '2026-05-19T07:00:00.000Z', 'details': '10.0.28000.2269:Security Update:https://support.microsoft.com/help/5095051', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12390', '12436', '12437', '20438', '20853'], 'known_affected': ['1', '2', '3', '4', '5']}}]} |
CVE-2026-45495 | msrc_CVE-2026-45495 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-06-01 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45495.json | ['Microsoft Edge (Chromium-based) 148.0.3967.70', 'Microsoft Edge (Chromium-based) <148.0.3967.70'] | 633c00656fbe43be4603d88c109ea2c27d969c9f64d2f4b6a7bcd9ae36e86c64 | 2026-05-29 20:36:27.484886+03:00 | 2026-06-10 15:29:50.715579+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45495', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-09T19:32:20.188Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-15T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-26T07:00:00.000Z', 'number': '2', 'summary': 'CWE added. Informational change only.', 'legacy_version': '1.1'}, {'date': '2026-06-01T07:00:00.000Z', 'number': '3', 'summary': 'Acknowledgement added. This is an informational change only.', 'legacy_version': '1.2'}], 'current_release_date': '2026-06-01T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45495.json', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) working with TrendAI Zero Day Initiative ']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Edge (Chromium-based)', 'branches': [{'name': '<148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) <148.0.3967.70', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) 148.0.3967.70', 'product_id': '11655'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45495', 'cwe': {'id': 'CWE-35', 'name': "Path Traversal: '.../...//'"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': '148.0.3967.70: 148.0.3967.70, 05/15/2026: 05/15/2026, 148.0.7778.168: 148.0.7778.168', 'title': 'What is the version information for this release?', 'category': 'faq'}], 'title': 'Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45495.json', 'summary': 'CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'date': '2026-05-15T07:00:00.000Z', 'details': '148.0.3967.70:Security Update:https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11655'], 'known_affected': ['1']}}]} |
CVE-2026-40411 | msrc_CVE-2026-40411 | Azure Virtual Network Gateway Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40411.json | ['Azure Virtual Network Gateway'] | 478de9fff8071284c90436458d0d3c939076b9c8cbb8ef169754284d91e1a773 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Virtual Network Gateway Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40411', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.936Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40411', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40411.json', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Shay Shavit with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Virtual Network Gateway', 'product': {'name': 'Azure Virtual Network Gateway', 'product_id': '21336'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40411', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Virtual Network Gateway Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.9, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.6, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21336']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40411', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40411.json', 'summary': 'CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21336']}}]} |
CVE-2026-47280 | msrc_CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-47280.json | ['Azure Resource Manager'] | b553e701f2024a5eaab68286b69b113b5c6046d686f0a3af445c2bb083ded028 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Resource Manager Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-47280', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.939Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47280', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-47280.json', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Resource Manager', 'product': {'name': 'Azure Resource Manager', 'product_id': '12443'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-47280', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Resource Manager Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12443']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47280', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-47280.json', 'summary': 'CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12443']}}]} |
CVE-2026-42827 | msrc_CVE-2026-42827 | M365 Copilot Information Disclosure Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42827.json | ['Microsoft 365 Copilot'] | 344625e176fa6ece4fd46538faf662254cafeab5fe26288805929652be4514ac | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'M365 Copilot Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42827', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.940Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42827', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42827.json', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft Office Security Team']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft 365 Copilot', 'product': {'name': 'Microsoft 365 Copilot', 'product_id': '16765'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42827', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'M365 Copilot Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['16765']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42827', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42827.json', 'summary': 'CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['16765']}}]} |
CVE-2026-41090 | msrc_CVE-2026-41090 | Microsoft Copilot Tampering Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41090.json | ['Microsoft 365 Copilot for iOS'] | beab95ffffaf3a4660ee0921c2d45c47ca99ab31757b7dd2b3796914da1d9c53 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Copilot Tampering Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41090', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.943Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41090.json', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft 365 Copilot for iOS', 'product': {'name': 'Microsoft 365 Copilot for iOS', 'product_id': '21043'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41090', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Copilot Tampering Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21043']}], 'threats': [{'details': 'Tampering', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41090', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41090.json', 'summary': 'CVE-2026-41090 Microsoft Copilot Tampering Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21043']}}]} |
CVE-2026-26147 | msrc_CVE-2026-26147 | Azure Stack HCI Information Disclosure Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-26147.json | ['Azure Stack HCI'] | 4a33658c1ccc40cb65fa7bb48f08e9055540e305aafc8c996002d9e3d8b08f66 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Stack HCI Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-26147', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.944Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26147', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-26147.json', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Michal Kamensky with Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Stack HCI', 'product': {'name': 'Azure Stack HCI', 'product_id': '12394'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-26147', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Stack HCI Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12394']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26147', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-26147.json', 'summary': 'CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12394']}}]} |
CVE-2026-33843 | msrc_CVE-2026-33843 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33843.json | ['Microsoft Entra ID'] | e5a1f55b022a578b3f4c3537e1941f2c77bb6ae0e5da03a33a01b55291a294e9 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33843', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.950Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33843.json', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://securesaml.com/">Alexander Tan</a> with SecureSAML']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Entra ID', 'product': {'name': 'Microsoft Entra ID', 'product_id': '12383'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33843', 'cwe': {'id': 'CWE-288', 'name': 'Authentication Bypass Using an Alternate Path or Channel'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 9.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'confidentialityImpact': 'HIGH'}, 'products': ['12383']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33843.json', 'summary': 'CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12383']}}]} |
CVE-2026-41104 | msrc_CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41104.json | ['Microsoft Planetary Computer Pro (GeoCatalog)'] | 6954e0d6af1b80275c9f332e7515c6d489e3750627926e203278ac7a00678c40 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Planetary Computer Pro Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41104', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.355Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41104', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41104.json', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/yanir_">Yanir Tsarimi</a> with <a href="https://enclave.ai/">Enclave</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Planetary Computer Pro (GeoCatalog)', 'product': {'name': 'Microsoft Planetary Computer Pro (GeoCatalog)', 'product_id': '21305'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41104', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Planetary Computer Pro Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21305']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41104', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41104.json', 'summary': 'CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21305']}}]} |
CVE-2026-42901 | msrc_CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42901.json | ['Microsoft Entra ID'] | 17252f2e1e3f5d301db4828847e508712ca672bd0fa001badf369c766a19a10d | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Entra ID Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42901', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.355Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42901', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42901.json', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Thomas Knudson']}, {'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Entra ID', 'product': {'name': 'Microsoft Entra ID', 'product_id': '12383'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42901', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Entra ID Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12383']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42901', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42901.json', 'summary': 'CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12383']}}]} |
CVE-2026-23663 | msrc_CVE-2026-23663 | Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-21 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23663.json | ['Microsoft Global Secure Access (GSA)'] | 825fcee894da925aab53dbf2c89eb81898276e343705b6d74f8748dc75cc0284 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-23663', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.356Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-21T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-21T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23663', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23663.json', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/vamsi-nukavarapu/">Vamsi Nukavarapu</a> with <a href="https://www.microsoft.com/">Microsoft</a>']}, {'names': ['Sriharsha Pallekonda with <a href="https://www.microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Global Secure Access (GSA)', 'product': {'name': 'Microsoft Global Secure Access (GSA)', 'product_id': '21057'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-23663', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['21057']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23663', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-23663.json', 'summary': 'CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['21057']}}]} |
CVE-2026-40367 | msrc_CVE-2026-40367 | Microsoft Word Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-20 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40367.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000'] | a0928c880566fba2dd45651479f8b60faf2a2194e5b524852ab12c7fb71e04d1 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40367', 'status': 'final', 'version': '3', 'generator': {'date': '2026-05-28T01:40:57.308Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-20T07:00:00.000Z', 'number': '2', 'summary': 'The security impact for this vulnerability has been revised from Critical to Important. In addition, the CVSS vector and FAQs were modified. This change does not affect the available security updates. Customers should continue to install the recommended updates to remain protected from this vulnerability.', 'legacy_version': '1.1'}, {'date': '2026-05-20T07:00:00.000Z', 'number': '3', 'summary': "Today's changes were made in error and have been reverted. This is an informational change only.", 'legacy_version': '1.2'}], 'current_release_date': '2026-05-20T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40367.json', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['0ccbbf129444eb66344ccafb92b00df4']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40367', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The attachment Preview Pane that is accessed when a user clicks to preview an attached file is an attack vector; however, the email Preview Pane itself is not.', 'title': 'Is the Attachment Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.', 'title': 'There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40367', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40367.json', 'summary': 'CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['13']}, {'url': 'https://support.microsoft.com/help/5002869', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002869', 'category': 'vendor_fix', 'product_ids': ['13']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['10']}, {'url': 'https://support.microsoft.com/help/5002872', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002872', 'category': 'vendor_fix', 'product_ids': ['10']}, {'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['12', '11', '9', '8', '6', '5', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['7', '1']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['4']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['15', '14']}], 'product_status': {'fixed': ['10746', '10747', '10950', '11573', '11574', '11585', '11762', '11763', '11951', '11952', '11953', '11961', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15']}}]} |
CVE-2026-33840 | msrc_CVE-2026-33840 | Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-19 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33840.json | ['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | b37b9402226498d489f3691da47608d362f3e32407c5a15adf4ad30eac23ffe6 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33840', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:56.979Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-19T07:00:00.000Z', 'number': '2', 'summary': 'Acknowledgement added. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-19T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33840', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33840.json', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/boolgombear/">Minjea Park</a>, <a href="https://www.linkedin.com/in/boolgombear/">ji9umi</a> and <a href="https://www.linkedin.com/in/boolgombear/">Jmini</a> with <a href="https://stealien.com/id/main">Stealien</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33840', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33840', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33840.json', 'summary': 'CVE-2026-33840 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]} |
CVE-2026-32175 | msrc_CVE-2026-32175 | .NET Core Tampering Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-19 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32175.json | ['.NET 10.0 installed on Windows 10.0.8', '.NET 10.0 installed on Windows <10.0.8', '.NET 8.0 installed on Windows 8.0.27', '.NET 8.0 installed on Windows <8.0.27', '.NET 9.0 installed on Windows 9.0.16', '.NET 9.0 installed on Windows <9.0.16', 'Microsoft Visual Studio 2022 version 17.12 17.12.20', 'Microsoft Visual Studio 2022 version 17.12 <17.12.20', 'Microsoft Visual Studio 2022 version 17.14 17.14.31', 'Microsoft Visual Studio 2022 version 17.14 <17.14.31', 'Microsoft Visual Studio 2026 version 18.5 18.5.3', 'Microsoft Visual Studio 2026 version 18.5 <18.5.3'] | da95c6e2e5c18fbd224359c02ca26250997afda279a60ba867937c26c6fba4c0 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': '.NET Core Tampering Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32175', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.209Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-19T07:00:00.000Z', 'number': '2', 'summary': 'Removed incorrectly added rows from the Security Updates table. This is an informational change only.', 'legacy_version': '2'}], 'current_release_date': '2026-05-19T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32175.json', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}, {'names': ['Radek Zikmund with Microsoft s.r.o.']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': '.NET 10.0 installed on Windows', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Windows <10.0.8', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Windows 10.0.8', 'product_id': '20837'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 8.0 installed on Windows', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Windows <8.0.27', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Windows 8.0.27', 'product_id': '12414'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Windows', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Windows <9.0.16', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Windows 9.0.16', 'product_id': '12434'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Visual Studio 2026 version 18.5', 'branches': [{'name': '<18.5.3', 'product': {'name': 'Microsoft Visual Studio 2026 version 18.5 <18.5.3', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '18.5.3', 'product': {'name': 'Microsoft Visual Studio 2026 version 18.5 18.5.3', 'product_id': '21244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Visual Studio 2022 version 17.14', 'branches': [{'name': '<17.14.31', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.14 <17.14.31', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '17.14.31', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.14 17.14.31', 'product_id': '16767'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Visual Studio 2022 version 17.12', 'branches': [{'name': '<17.12.20', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.12 <17.12.20', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '17.12.20', 'product': {'name': 'Microsoft Visual Studio 2022 version 17.12 17.12.20', 'product_id': '12459'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32175', 'cwe': {'id': 'CWE-36', 'name': 'Absolute Path Traversal'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': '.NET Core Tampering Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C', 'temporalScore': 3.8, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6']}], 'threats': [{'details': 'Tampering', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32175', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32175.json', 'summary': 'CVE-2026-32175 .NET Core Tampering Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5093446', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.8:Security Update:https://support.microsoft.com/help/5093446', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5093447', 'date': '2026-05-12T07:00:00.000Z', 'details': '8.0.27:Security Update:https://support.microsoft.com/help/5093447', 'category': 'vendor_fix', 'product_ids': ['6']}, {'url': 'https://support.microsoft.com/help/5093448', 'date': '2026-05-12T07:00:00.000Z', 'details': '9.0.16:Security Update:https://support.microsoft.com/help/5093448', 'category': 'vendor_fix', 'product_ids': ['5']}, {'url': 'https://learn.microsoft.com/en-us/visualstudio/releases/2026/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '18.5.3:Security Update:https://learn.microsoft.com/en-us/visualstudio/releases/2026/release-notes', 'category': 'vendor_fix', 'product_ids': ['1']}, {'url': 'https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '17.14.31:Security Update:https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '17.12.20:Security Update:https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes', 'category': 'vendor_fix', 'product_ids': ['4']}], 'product_status': {'fixed': ['12414', '12434', '12459', '16767', '20837', '21244'], 'known_affected': ['1', '2', '3', '4', '5', '6']}}]} |
CVE-2026-42834 | msrc_CVE-2026-42834 | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-19 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42834.json | ['Windows Admin Center in Azure Portal 0.72.0.0.', 'Windows Admin Center in Azure Portal <0.72.0.0.'] | 552ae45430f004ae4ff3509d7f483d33fc760b5cc095286af6d2517690b46489 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42834', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.349Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-19T07:00:00.000Z', 'number': '1', 'summary': 'Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.', 'legacy_version': '1'}], 'current_release_date': '2026-05-19T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42834', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42834.json', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/crispr_x">BochengXiang(@Crispr)</a> with FDU']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Admin Center in Azure Portal', 'branches': [{'name': '<0.72.0.0.', 'product': {'name': 'Windows Admin Center in Azure Portal <0.72.0.0.', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '0.72.0.0.', 'product': {'name': 'Windows Admin Center in Azure Portal 0.72.0.0.', 'product_id': '12518'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42834', 'cwe': {'id': 'CWE-59', 'name': "Improper Link Resolution Before File Access ('Link Following')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}, {'text': 'Customers should install the latest version of the Windows Admin Center extension through the Azure Portal. There is no direct download link; instead, customers need to open the Extensions + Applications blade for their virtual machine in the Azure Portal and search for the extension named AdminCenter (Microsoft.AdminCenter.AdminCenter). From there, they can add or update the extension following the standard Azure VM extension installation process described here.', 'title': 'What customer action needs to take place to mitigate the vulnerability?', 'category': 'faq'}], 'title': 'Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42834', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42834.json', 'summary': 'CVE-2026-42834 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/extension-release-notes', 'date': '2026-05-19T07:00:00.000Z', 'details': '0.72.0.0.:Security Update:https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/extension-release-notes', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12518'], 'known_affected': ['1']}}]} |
CVE-2026-42822 | msrc_CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-18 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42822.json | ['Azure Local 2604.2.25645', 'Azure Local <2604.2.25645'] | d199c9834e91706fef2c256e0bab47cfa9bad2ead3cc215314336a8cc876561a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42822', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.347Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-18T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-18T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42822.json', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Local', 'branches': [{'name': '<2604.2.25645', 'product': {'name': 'Azure Local <2604.2.25645', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '2604.2.25645', 'product': {'name': 'Azure Local 2604.2.25645', 'product_id': '20844'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42822', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'For Azure Local Disconnected Operations (ALDO) customers:\nTo protect against this vulnerability, customers must update their Azure Local Disconnected Operations (ALDO) environment to the latest available release (version 2604 or later). Updates are not available as standalone patches and must be applied as a full system update through the Azure portal. ALDO is a restricted offering, and updates are only available to approved customers via allow-listing.\nCustomers should follow Microsoft guidance to obtain access and apply the update, using the following documentation:\nHow to deploy Disconnected Operations for Azure Local\nHow to update Disconnected Operations for Azure Local', 'title': 'How do I protect myself from this vulnerability?', 'category': 'faq'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could gain elevated privileges beyond those normally available to them, allowing actions such as accessing restricted information or performing operations that are typically limited to more highly privileged users or administrators.', 'title': 'What privileges could be gained by an attacker who successfully exploited the vulnerability?', 'category': 'faq'}, {'text': 'The most realistic exploitation scenario involves a malicious or compromised insider with existing access to the customer’s environment.\nAn attacker could exploit this vulnerability if they:\nAlready have access to the internal environment (e.g., an internal user, contractor, or compromised account)., Possess or can obtain relevant identity information such as tenant identifiers, user identifiers, credentials, or tokens., Use this access to interact with and attempt exploitation within the Azure Local Disconnected Operations (ALDO) environment.\nBecause an insider or compromised internal identity already satisfies many of the environmental and authentication requirements, they may bypass several of the barriers that would otherwise make exploitation more difficult.\nIn external attacker scenarios, exploitation is significantly more constrained. An attacker would first need to:\nGain access to the customer’s internal network (which may require physical presence or prior compromise), and, Obtain valid identity context within the environment.\nAdditionally, Azure Local Disconnected Operations is designed to operate in a disconnected and isolated configuration, limiting direct external exposure and reducing the likelihood of opportunistic remote exploitation.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10.0, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42822.json', 'summary': 'CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-whats-new?view=azloc-2604', 'date': '2026-05-18T07:00:00.000Z', 'details': '2604.2.25645:Security Update:https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-whats-new?view=azloc-2604', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['20844'], 'known_affected': ['1']}}]} |
CVE-2026-42833 | msrc_CVE-2026-42833 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-13 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42833.json | ['Microsoft Dynamics 365 (on-premises) version 9.1 9.1.45.11', 'Microsoft Dynamics 365 (on-premises) version 9.1 <9.1.45.11'] | 526d1c437389262bb1b9538bbbd7bdc8b1789afa856c5f6106a61e3f91dd6dc2 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42833', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.339Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-13T07:00:00.000Z', 'number': '2', 'summary': 'Updated the fixed version number. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-13T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42833.json', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/hoangnx99">nxhoang99</a> and <a href="hoang.ha.handle@gmail.com">hoangha<a/> with <a href="https://lab.viettelcybersecurity.com/">VCSLab of Viettel Cyber Security</a>']}, {'names': ['<a href="https://www.linkedin.com/in/talha--gunay/">TALHA GÜNAY</a>']}, {'names': ['f7d8c52bec79e42795cf15888b85cbad']}, {'names': ['<a href="https://twitter.com/hoangnx99">nxhoang99</a> and <a href="hoang.ha.handle@gmail.com">hoangha<a/> with <a href="https://lab.viettelcybersecurity.com/">VCSLab of Viettel Cyber Security</a>']}, {'names': ['Kentaro Kawane with <a href="https://gmo-cybersecurity.com/">GMO Cybersecurity by Ierae, Inc.</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Dynamics 365 (on-premises) version 9.1', 'branches': [{'name': '<9.1.45.11', 'product': {'name': 'Microsoft Dynamics 365 (on-premises) version 9.1 <9.1.45.11', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '9.1.45.11', 'product': {'name': 'Microsoft Dynamics 365 (on-premises) version 9.1 9.1.45.11', 'product_id': '11921'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42833', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker with System Administrator privileges could modify specific data associated with background operations through the CRM web interface. When the system later processes this data, it may be deserialized without proper validation, allowing the attacker to trigger unauthorized commands on the CRM server.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'This vulnerability could lead to the attacker gaining the ability to interact with other tenant’s applications and content.', 'title': 'According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.9, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42833.json', 'summary': 'CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5078943', 'date': '2026-05-12T07:00:00.000Z', 'details': '9.1.45.11:Security Update:https://support.microsoft.com/help/5078943', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11921'], 'known_affected': ['1']}}]} |
CVE-2026-32161 | msrc_CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-15 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32161.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 87a5f11375e42f5b95100730a29a5ff65613ab863993ecf22c4f8e10dca698f2 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32161', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.197Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-15T07:00:00.000Z', 'number': '2', 'summary': 'Updated Hotpatch links. This is in informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32161', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32161.json', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/danielr1123/">Daniel R</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32161', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploitation requires specific conditions, including particular network configurations and timing conditions, and has only been observed in limited scenarios. This means an attacker cannot reliably exploit the issue in all environments and may need favorable setup or circumstances for it to work.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.', 'title': 'According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32161', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32161.json', 'summary': 'CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-40379 | msrc_CVE-2026-40379 | Azure Entra ID Spoofing Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-15 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40379.json | ['Microsoft Entra ID'] | 356bac41dff5817dd34a2eff8170f0e15ee0e085b089798c34fbff29c48b53d4 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Not required. The vulnerability documented by this CVE requires no customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Entra ID Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40379', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:56.932Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-07T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-15T07:00:00.000Z', 'number': '2', 'summary': 'Corrected CVE title. This is an informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40379.json', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}, {'names': ['Thomas Knudson']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Entra ID', 'product': {'name': 'Microsoft Entra ID', 'product_id': '12383'}, 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40379', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.\nPlease see Toward greater transparency: Unveiling Cloud Service CVEs for more information.', 'title': 'Why are there no links to an update or instructions with steps that must be taken to protect from this vulnerability?', 'category': 'faq'}], 'title': 'Azure Entra ID Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.3, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['12383']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40379.json', 'summary': 'CVE-2026-40379 Azure Entra ID Spoofing Vulnerability - CSAF', 'category': 'self'}], 'product_status': {'fixed': ['12383']}}]} |
CVE-2026-32170 | msrc_CVE-2026-32170 | Windows Rich Text Edit Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-15 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32170.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 993cbc7855bf20c67579576d7199fe8588654b3679cc4970e5bf4314ce7fc967 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Rich Text Edit Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32170', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-28T01:40:57.207Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}, {'date': '2026-05-15T07:00:00.000Z', 'number': '2', 'summary': 'Updated Hotpatch links. This is in informational change only.', 'legacy_version': '1.1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32170', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32170.json', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32170', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain administrator privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited the vulnerability?', 'category': 'faq'}, {'text': 'An authorized attacker must send a victim a malicious and specially crafted file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An authorized attacker must send the user a malicious file and convince the user to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows Rich Text Edit Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.7, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 5.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32170', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32170.json', 'summary': 'CVE-2026-32170 Windows Rich Text Edit Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-45492 | msrc_CVE-2026-45492 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Moderate | 2026-05-12 10:00:00+03:00 | 2026-05-15 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45492.json | ['Microsoft Edge (Chromium-based) 148.0.3967.70', 'Microsoft Edge (Chromium-based) <148.0.3967.70'] | 8b486ea59f2830ee166dcc4022505175f87863dd0af1c38cb25709b2c8f86ad7 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-45492', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.342Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-15T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-15T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45492', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45492.json', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) working with TrendAI Zero Day Initiative ']}, {'names': ['Anonymous ']}], 'aggregate_severity': {'text': 'Moderate', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Edge (Chromium-based)', 'branches': [{'name': '<148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) <148.0.3967.70', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '148.0.3967.70', 'product': {'name': 'Microsoft Edge (Chromium-based) 148.0.3967.70', 'product_id': '11655'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-45492', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability).', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?', 'category': 'faq'}, {'text': 'An authenticated local attacker can disable or enable Windows VBS without administrative privileges, resulting in bypass of platform security hardening. This does not grant direct code execution as another user but weakens system security guarantees, enabling follow‑on attacks.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}, {'text': '148.0.3967.70: 148.0.3967.70, 05/15/2026: 05/15/2026, 148.0.7778.168: 148.0.7778.168', 'title': 'What is the version information for this release?', 'category': 'faq'}], 'title': 'Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.7, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45492', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-45492.json', 'summary': 'CVE-2026-45492 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'date': '2026-05-15T07:00:00.000Z', 'details': '148.0.3967.70:Security Update:https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11655'], 'known_affected': ['1']}}]} |
CVE-2026-41615 | msrc_CVE-2026-41615 | Microsoft Authenticator Information Disclosure Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-14 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41615.json | ['Microsoft Authenticator for Android 6.2605.2973', 'Microsoft Authenticator for Android <6.2605.2973', 'Microsoft Authenticator for IOS 6.8.47', 'Microsoft Authenticator for IOS <6.8.47'] | a6a8a727e5ac53d51b00b36f4993d40c7108484abdf8c99cfcd0c28dae8724f2 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Authenticator Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41615', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.229Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-14T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-14T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41615.json', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Sridhar Periyasamy']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Authenticator for Android', 'branches': [{'name': '<6.2605.2973', 'product': {'name': 'Microsoft Authenticator for Android <6.2605.2973', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '6.2605.2973', 'product': {'name': 'Microsoft Authenticator for Android 6.2605.2973', 'product_id': '12289'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Authenticator for IOS', 'branches': [{'name': '<6.8.47', 'product': {'name': 'Microsoft Authenticator for IOS <6.8.47', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '6.8.47', 'product': {'name': 'Microsoft Authenticator for IOS 6.8.47', 'product_id': '20927'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41615', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'This vulnerability could expose a sign-in access token for a user’s work account. If disclosed, that token could allow access to data and services that the user is authorized to use, potentially including sensitive organizational information.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could attempt to trick a user into interacting with a malicious request that appears legitimate. When the user approves the request, the attacker could cause the app to obtain an access token on the user’s behalf and send it to a location controlled by the attacker, without the user being clearly informed about what access is being granted.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'Users who have automatic app updates enabled on their Android device will receive the fix without any action required. Users who do not have auto-update enabled must manually update the Microsoft Authenticator app to the latest version via the Google Play Store to ensure they receive the fix.', 'title': 'Do users need to take any action to receive the fix for the Authenticator app issue on Android?', 'category': 'faq'}], 'title': 'Microsoft Authenticator Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.6, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.3, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41615.json', 'summary': 'CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.azure.authenticator', 'date': '2026-05-14T07:00:00.000Z', 'details': '6.2605.2973:Security Update:https://play.google.com/store/apps/details?id=com.azure.authenticator', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://apps.apple.com/us/app/microsoft-authenticator/id983156458', 'date': '2026-05-14T07:00:00.000Z', 'details': '6.8.47:Security Update:https://apps.apple.com/us/app/microsoft-authenticator/id983156458', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12289', '20927'], 'known_affected': ['1', '2']}}]} |
CVE-2026-32204 | msrc_CVE-2026-32204 | Azure Monitor Agent Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32204.json | ['Azure Monitor Agent 1.14.0', 'Azure Monitor Agent <1.14.0'] | 37742818a30275f1543cf1675ada62efa51a681739792a10dfde70a31ce443e6 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Monitor Agent Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-32204', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.952Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32204', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32204.json', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['P1hcn']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Monitor Agent', 'branches': [{'name': '<1.14.0', 'product': {'name': 'Azure Monitor Agent <1.14.0', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.14.0', 'product': {'name': 'Azure Monitor Agent 1.14.0', 'product_id': '12331'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-32204', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': "An attacker who successfully exploited the vulnerability could elevate their privileges to 'root' user.", 'title': 'What privileges could an attacker gain with successful exploitation?', 'category': 'faq'}, {'text': 'An attacker could send specially crafted configuration messages to a locally running Azure Monitor Agent service that does not strictly validate incoming requests. By doing so, the attacker may be able to write files on the affected system, which could then be used to run unauthorized code.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure Monitor Agent Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32204', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-32204.json', 'summary': 'CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://eng.ms/docs/products/geneva/collect/references/amacoreagent/release-notes', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.14.0:Security Update:https://eng.ms/docs/products/geneva/collect/references/amacoreagent/release-notes', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12331'], 'known_affected': ['1']}}]} |
CVE-2026-33834 | msrc_CVE-2026-33834 | Windows Event Logging Service Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33834.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 2cd57f8373d7f53beb2240cd7d30b11f1a34083e018518754a506f66e8f75246 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Event Logging Service Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33834', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.972Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33834', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33834.json', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/ecthr0s">George Hughey</a> with MSRC Vulnerabilities & Mitigations']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33834', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Event Logging Service Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33834', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33834.json', 'summary': 'CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-33839 | msrc_CVE-2026-33839 | Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33839.json | ['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 39fa3dc278825fb94cf87855714450348550f81ac8be44c10e694b041669eb94 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33839', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.978Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33839', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33839.json', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33839', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33839', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33839.json', 'summary': 'CVE-2026-33839 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]} |
CVE-2026-34329 | msrc_CVE-2026-34329 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34329.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | a105c8b25926adac89b666e1f728b865cd199c49ae7666d116407896541074c4 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34329', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.981Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34329', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34329.json', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/4zure9">Azure Yang</a> with <a href="http://www.cyberkl.com/">Kunlun Lab</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34329', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could send a specially crafted message over the network to a system running the Windows Message Queuing (MSMQ) service. This message is processed by the MSMQ service and triggers a memory corruption condition, which could allow the attacker to run code on the affected system.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.', 'title': 'According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34329', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34329.json', 'summary': 'CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34330 | msrc_CVE-2026-34330 | Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34330.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | d9b37eadcbcefc084ba6a43e6de3ea1401624838886cdddc4e578bdc5e5bd166 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34330', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.994Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34330', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34330.json', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34330', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34330', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34330.json', 'summary': 'CVE-2026-34330 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34331 | msrc_CVE-2026-34331 | Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34331.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | cfc5b15ed7a53926ee06ecb3797cb164c3192cd8d2927910b76847e12a7dfc27 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34331', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:56.996Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34331', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34331.json', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34331', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34331', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34331.json', 'summary': 'CVE-2026-34331 Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34333 | msrc_CVE-2026-34333 | Windows Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34333.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 6d7369c185807e9c1de90367970ab5b5d608ebfd427bf7629c7bc3e86fa67f91 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34333', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.003Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34333', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34333.json', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34333', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34333', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34333.json', 'summary': 'CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34342 | msrc_CVE-2026-34342 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34342.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 13d29563b90f0593939bb37e5e26f50db5e2ea22817b2a3f7983298fb72b7f7f | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Print Spooler Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34342', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.005Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34342', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34342.json', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Marcin Wiazowski working with <a href="https://www.zerodayinitiative.com/">TrendAI Zero Day Initiative</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34342', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could elevate from a low integrity level up to a medium integrity level.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Print Spooler Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34342', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34342.json', 'summary': 'CVE-2026-34342 Windows Print Spooler Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34343 | msrc_CVE-2026-34343 | Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34343.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 39eabd32800ca0a524767ff504bb6bf0ebc9f41643b246ca52921da8287414d8 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34343', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.010Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34343', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34343.json', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://bsky.app/profile/hexnomad.bsky.social">Erik Egsgard</a> with <a href="https://fieldeffect.com/">Field Effect</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34343', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34343', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34343.json', 'summary': 'CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34344 | msrc_CVE-2026-34344 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34344.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | fc90f7a449bb593886166339a8b831c7c6d1da4cda66165a89b01e5beeb062b5 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34344', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.022Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34344', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34344.json', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/scwuaptx">Angelboy (@scwuaptx)</a> with <a href="https://devco.re/">DEVCORE</a>']}, {'names': ['Puponia']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34344', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34344', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34344.json', 'summary': 'CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34345 | msrc_CVE-2026-34345 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34345.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | d196ca1ab300d4750124830a791d9ec3b25385184406a0f440fd11a8c942eea9 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34345', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.023Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34345.json', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/scwuaptx">Angelboy (@scwuaptx)</a> with <a href="https://devco.re/">DEVCORE</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34345', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34345', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34345.json', 'summary': 'CVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}], 'product_status': {'fixed': ['10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}}]} |
CVE-2026-34347 | msrc_CVE-2026-34347 | Windows Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34347.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 78e5b0d4cda108205d37517e54316f44fc9676df93938a4b3aeeffe66473dc4f | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34347', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.034Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34347', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34347.json', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['wenqunwang with China Telecom Research Institute']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34347', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34347', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34347.json', 'summary': 'CVE-2026-34347 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34350 | msrc_CVE-2026-34350 | Windows Storport Miniport Driver Denial of Service Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34350.json | ['Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 2537f00663502a6ecfc0f6698f50db916e2a550349a80df9a12c43ed7d38976e | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Storport Miniport Driver Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34350', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.035Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34350', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34350.json', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft Offensive Research & Security Engineering']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34350', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'To trigger this vulnerability, a user must actively connect to the affected server and run a specific command. The vulnerability cannot be triggered automatically or in the background; it only occurs when a user intentionally interacts with the server using this command.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Windows Storport Miniport Driver Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34350', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34350.json', 'summary': 'CVE-2026-34350 Windows Storport Miniport Driver Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}], 'product_status': {'fixed': ['12436', '12437'], 'known_affected': ['1', '2']}}]} |
CVE-2026-34351 | msrc_CVE-2026-34351 | Windows TCP/IP Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34351.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 2e97712062c63a8dc7319f1298a89b1f19e47257f872ae81bf1a3c43941f1086 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34351', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.036Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34351', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34351.json', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['hazard']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34351', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34351', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34351.json', 'summary': 'CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-35415 | msrc_CVE-2026-35415 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35415.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 5b788fae481ea0aa18cca336400393076b2112f70353f8322b5f03fed72e8b77 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Storage Spaces Controller Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35415', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.037Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35415', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35415.json', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Jan Vojtesek with <a href="http://sentinelone.com/">SentinelOne</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35415', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Storage Spaces Controller Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35415', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35415.json', 'summary': 'CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}}]} |
CVE-2026-35416 | msrc_CVE-2026-35416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35416.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 67734ebebbb72228694cd154d412c91e0f40a9138a916dcf63b47e5e4124402a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35416', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.045Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35416', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35416.json', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/scwuaptx">Angelboy (@scwuaptx)</a> with <a href="https://devco.re/">DEVCORE</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35416', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35416', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35416.json', 'summary': 'CVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-41614 | msrc_CVE-2026-41614 | M365 Copilot for Desktop Spoofing Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41614.json | ['M365 Copilot for Desktop 19.2604.43111.0', 'M365 Copilot for Desktop <19.2604.43111.0'] | cbe5453ac5a1386bd081f7895527428907768e920b7004ec5a937b8d7f794a17 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'M365 Copilot for Desktop Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41614', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.191Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41614.json', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Artem Shymshyrian (Xtytia0922 - V-Spot)']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'M365 Copilot for Desktop', 'branches': [{'name': '<19.2604.43111.0', 'product': {'name': 'M365 Copilot for Desktop <19.2604.43111.0', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '19.2604.43111.0', 'product': {'name': 'M365 Copilot for Desktop 19.2604.43111.0', 'product_id': '21292'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41614', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'M365 Copilot for Desktop Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.2, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.4, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41614', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41614.json', 'summary': 'CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://apps.microsoft.com/detail/9wzdncrd29v9?hl=en-us&gl=IE&ocid=pdpshare', 'date': '2026-05-12T07:00:00.000Z', 'details': '19.2604.43111.0:Security Update:https://apps.microsoft.com/detail/9wzdncrd29v9?hl=en-us&gl=IE&ocid=pdpshare', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['21292'], 'known_affected': ['1']}}]} |
CVE-2026-35417 | msrc_CVE-2026-35417 | Windows Win32k Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35417.json | ['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 6b1e28fa63acdde0a054f901d35e61554f28963dd6076afbf67fc6bb71a4297a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35417', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.057Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35417', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35417.json', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Owen McCullough']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35417', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Win32k Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35417', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35417.json', 'summary': 'CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]} |
CVE-2026-35418 | msrc_CVE-2026-35418 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35418.json | ['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 46ef89e772340db5a104a0b7469186ad2ccad16878bb5c7666b5876ca8761693 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35418', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.058Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35418', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35418.json', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35418', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35418', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35418.json', 'summary': 'CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '15', '16']}, {'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['20', '23', '22', '21']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['10', '11']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]} |
CVE-2026-35419 | msrc_CVE-2026-35419 | Windows DWM Core Library Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35419.json | ['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 378e1f2f767fcfa0215766d40334cbc455f94dffe94f77c763475445736bd55b | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DWM Core Library Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35419', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.059Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35419', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35419.json', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/immortalp0ny">Sergey immortalp0ny Tarasov</a> with <a href="https://global.ptsecurity.com/">Positive Technologies</a>']}, {'names': ['namnp with <a href="https://x.com/vcslab">Viettel Cyber Security</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35419', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}], 'title': 'Windows DWM Core Library Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35419', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35419.json', 'summary': 'CVE-2026-35419 Windows DWM Core Library Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]} |
CVE-2026-35420 | msrc_CVE-2026-35420 | Windows Kernel Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35420.json | ['Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | c9fe3be22b6cd0ec873b58fd5a4a0db34a85a88bf5b2fe2018f6be32b777a311 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Kernel Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35420', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.060Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35420', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35420.json', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://linkedin.com/in/jongseongkim">Jongseong Kim (nevul37), SEC-agent team</a>']}, {'names': ['<a href="https://linkedin.com/in/hwiwonlee">Hwiwon Lee (hwiwonl), SEC-agent team</a>']}, {'names': ['Younggi Park (grill66), SEC-agent team']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35420', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Kernel Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35420', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35420.json', 'summary': 'CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['7', '6']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['9', '8']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['13', '12']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['11', '10']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10855', '11571', '11572', '11923', '11924', '12244', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]} |
CVE-2026-35421 | msrc_CVE-2026-35421 | Windows GDI Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35421.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | ab8eeb0cf3f46c8579f36889c748cd13a02de8c8b70a8949ea50630562cf1e2e | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows GDI Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35421', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.061Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35421', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35421.json', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['pwn2addr']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35421', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}, {'text': 'For this vulnerability to be exploited, a user would need to open or otherwise process a specially crafted Enhanced Metafile (EMF) file using Microsoft Paint. This action is necessary to trigger the affected graphics functionality in the Windows component.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Windows GDI Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35421', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35421.json', 'summary': 'CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-35422 | msrc_CVE-2026-35422 | Windows TCP/IP Driver Security Feature Bypass Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35422.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | c9da465429e6b4e020af4c96aabaa081f8c1c038f5b4c0909dc2fb8b72b71916 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Driver Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35422', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.076Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35422', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35422.json', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35422', 'cwe': {'id': 'CWE-288', 'name': 'Authentication Bypass Using an Alternate Path or Channel'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could bypass IPsec execution policy enforcement, allowing them to circumvent the rules and restrictions that govern how IPsec is applied. This could enable unauthorized or untrusted network communications to proceed without the intended security protections being enforced.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Driver Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35422', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35422.json', 'summary': 'CVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-35423 | msrc_CVE-2026-35423 | Windows 11 Telnet Client Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35423.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 7109adb9bcc35a0e9360451be40c32e5dd7af4fd7cbf4dcce963a8f4495c0032 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows 11 Telnet Client Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35423', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.085Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35423', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35423.json', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35423', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to access limited sensitive information from system memory and may cause intermittent interruptions or reduced performance in the affected application. However, it would not allow the attacker to modify data.', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), no loss to integrity (I:N) and lead to some loss of availability (A:L). What is the impact of this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could potentially read limited portions of memory from the affected system, which may include sensitive information being processed by the Telnet client at the time of the connection.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'For this vulnerability to be exploited, a user would need to initiate a Telnet connection to a malicious or compromised server, allowing specially crafted authentication responses to be processed by the Telnet client. Successful exploitation requires a user to take an action before the vulnerability can be triggered.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Windows 11 Telnet Client Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C', 'temporalScore': 4.7, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35423', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35423.json', 'summary': 'CVE-2026-35423 Windows 11 Telnet Client Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-35424 | msrc_CVE-2026-35424 | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35424.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | ab13fb195cd5872b18f2c0a310bf2ca3dbd2e8a18a39d55a7df56d7c3847e8ac | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35424', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.091Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35424', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35424.json', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35424', 'cwe': {'id': 'CWE-401', 'name': 'Missing Release of Memory after Effective Lifetime'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35424', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35424.json', 'summary': 'CVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-35438 | msrc_CVE-2026-35438 | Windows Admin Center Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35438.json | ['Windows Admin Center 2.6.5.16', 'Windows Admin Center <2.6.5.16'] | 12bae47b7d6f62cdf00e626849e7d6011f1b4039aa5cda95819f21b38c16cc2b | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Admin Center Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35438', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.099Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35438', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35438.json', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['sho odagiri with <a href="https://gmo-cybersecurity.com/">GMO Cybersecurity by Ierae inc</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Admin Center', 'branches': [{'name': '<2.6.5.16', 'product': {'name': 'Windows Admin Center <2.6.5.16', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '2.6.5.16', 'product': {'name': 'Windows Admin Center 2.6.5.16', 'product_id': '11629'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35438', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation primarily allows a low-privileged attacker to perform unauthorized actions that affect the system’s integrity and availability. Specifically, the attacker could install an arbitrary available Windows Admin Center version from the update catalog, which can overwrite or alter the existing installation and disrupt normal operation. This is why integrity and availability are rated as high impact.\nThe impact to confidentiality is considered limited because exploitation does not directly expose sensitive information. However, there is a potential for indirect confidentiality impact if the attacker installs a version that contains known information disclosure issues or weaker security protections.', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to a minor loss of confidentiality (C:L), but major integrity (I:H), and availability (A:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An authenticated attacker with low privileges could gain the ability to perform actions that should require higher‑level permissions. Specifically, they could install an arbitrary available Windows Admin Center version from the update catalog. This includes reinstalling the current version, installing older versions, or installing any other available version that is not the latest—including versions that may contain known vulnerabilities.\nThis effectively allows the attacker to make unauthorized changes to the software configuration beyond what their assigned access level is intended to permit.', 'title': 'What privileges could be gained by an attacker who successfully exploited the vulnerability?', 'category': 'faq'}, {'text': 'An authenticated attacker with low‑privileged access could exploit this vulnerability by sending a specially crafted request to the affected Windows Admin Center update API, allowing them to perform actions that their assigned permissions should not normally permit.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows Admin Center Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35438', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35438.json', 'summary': 'CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://aka.ms/wac2511', 'date': '2026-05-12T07:00:00.000Z', 'details': '2.6.5.16:Security Update:https://aka.ms/wac2511', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11629'], 'known_affected': ['1']}}]} |
CVE-2026-35439 | msrc_CVE-2026-35439 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35439.json | ['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280'] | bdb9ef016023880cfd69ba0b74456d8d311507851da1c80ba97bedd8cee8de70 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35439', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.100Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35439.json', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['f7d8c52bec79e42795cf15888b85cbad']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35439', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35439', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35439.json', 'summary': 'CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]} |
CVE-2026-35440 | msrc_CVE-2026-35440 | Microsoft Word Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35440.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000'] | 1015c70ae5c4ea8e1b84c2e8310d95dcf14d4e52227a9bf730d88e76e4fa7dca | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-35440', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.100Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35440.json', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-35440', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the local memory address.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker must send a user a malicious email and convince a user to reply it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-35440.json', 'summary': 'CVE-2026-35440 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['8', '7', '6', '5', '4', '3', '2', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['10', '9']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11952', '11953', '12420', '12421'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}}]} |
CVE-2026-40360 | msrc_CVE-2026-40360 | Microsoft Excel Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40360.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Excel 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Excel 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Excel 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Excel 2016 (64-bit edition) <16.0.5552.1000', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Office Online Server 16.0.10417.20128', 'Office Online Server <16.0.10417.20128'] | 9022091a73ea458201b42e8ea4e3fa38c5a70a99ac24f4ade2e73279a057befb | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Excel Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40360', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.101Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40360', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40360.json', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/dnpushme">f4 & Zhiniang Peng with HUST</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Office Online Server', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Office Online Server <16.0.10417.20128', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Office Online Server 16.0.10417.20128', 'product_id': '10836'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Excel 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10739'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Excel 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Excel 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10740'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40360', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'An attacker must send a user a malicious Office file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Excel Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40360', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40360.json', 'summary': 'CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002871', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002871', 'category': 'vendor_fix', 'product_ids': ['11']}, {'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['10', '9', '8', '7', '5', '4', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['6', '1']}, {'url': 'https://support.microsoft.com/help/5002865', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002865', 'category': 'vendor_fix', 'product_ids': ['13', '12']}], 'product_status': {'fixed': ['10739', '10740', '10836', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]} |
CVE-2026-40363 | msrc_CVE-2026-40363 | Microsoft Office Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40363.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Office 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Office 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Office 2016 (64-bit edition) <16.0.5552.1000', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Office for Android 16.0.19822.20190', 'Microsoft Office for Android <16.0.19822.20190'] | a045ea2ae46411628b904579e38352c8d771cf14f450b1363a277b688036b5de | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40363', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.102Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40363', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40363.json', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/lmksecurity">Jeongmin Choi</a> with <a href="https://s2w.inc/ko/">S2W</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10753'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Office 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10754'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android <16.0.19822.20190', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android 16.0.19822.20190', 'product_id': '12155'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40363', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes, the Preview Pane is an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40363', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40363.json', 'summary': 'CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['11', '10', '9', '8', '6', '5', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['7', '1']}, {'url': 'https://support.microsoft.com/help/5002866', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002866', 'category': 'vendor_fix', 'product_ids': ['13', '12']}, {'url': 'https://support.google.com/googleplay/answer/113412?hl=en', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://support.google.com/googleplay/answer/113412?hl=en', 'category': 'vendor_fix', 'product_ids': ['4']}], 'product_status': {'fixed': ['10753', '10754', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12155', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]} |
CVE-2026-40364 | msrc_CVE-2026-40364 | Microsoft Word Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40364.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000'] | 87db264b58712a89db1fe51be1ead5174c7f3acccd8197b5ea6ccbd1200bcd8a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40364', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.106Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40364', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40364.json', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40364', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes, the Preview Pane is an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.\nFor example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40364', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40364.json', 'summary': 'CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['10', '9', '8', '7', '5', '4', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['6', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['12', '11']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}}]} |
CVE-2026-40366 | msrc_CVE-2026-40366 | Microsoft Word Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40366.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000'] | 4eed9303a8ad43404dddea991c0ba24d85353a098452261e6b658e42cb8f2038 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40366', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.107Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40366', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40366.json', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40366', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes, the Preview Pane is an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Word Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.4, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40366', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40366.json', 'summary': 'CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['10', '9', '8', '7', '5', '4', '3', '2']}, {'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['6', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['12', '11']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11951', '11952', '11953', '12420', '12421', '12440'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12']}}]} |
CVE-2026-40368 | msrc_CVE-2026-40368 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40368.json | ['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280'] | 8a98b5deb7266900a99d6a7c287e35c7030646a42a994db5bcaac08a3605b406 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40368', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.110Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40368', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40368.json', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Butterfly']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40368', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This attack requires a client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.0, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.0, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40368', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40368.json', 'summary': 'CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]} |
CVE-2026-40374 | msrc_CVE-2026-40374 | Microsoft Power Automate Desktop Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40374.json | ['Power Automate for Desktop 2.67', 'Power Automate for Desktop <2.67'] | 9e4efd4e75b8d269fcd030b41f5e22477ebb4389b213fca5e589bf1005efbb1b | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Power Automate Desktop Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40374', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.110Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40374.json', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Ioannis Panagiotopoulos with Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Power Automate for Desktop', 'branches': [{'name': '<2.67', 'product': {'name': 'Power Automate for Desktop <2.67', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '2.67', 'product': {'name': 'Power Automate for Desktop 2.67', 'product_id': '12410'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40374', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This vulnerability could expose values stored in variables that were marked as “Sensitive” within Power Automate Desktop flows. Due to a logging issue, these sensitive variable values may appear in execution logs uploaded to the Power Automate portal and be viewable by users with Owner, Co-Owner, or Runner permissions for the affected desktop flow.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Power Automate Desktop Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40374', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40374.json', 'summary': 'CVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate-desktop', 'date': '2026-05-12T07:00:00.000Z', 'details': '2.67:Security Update:https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate-desktop', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12410'], 'known_affected': ['1']}}]} |
CVE-2026-40377 | msrc_CVE-2026-40377 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40377.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 0112897ceff381e7988a991398cfebe415b7122f73cb8404ef0cd926b8414fdd | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40377', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.112Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40377', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40377.json', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/brucedang">Bruce Dang</a> with <a href="https://www.calif.io/">Calif.io</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40377', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40377', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40377.json', 'summary': 'CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-40380 | msrc_CVE-2026-40380 | Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40380.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 5b70879cb4a264f192b1b324b3015ce3cb161c8844d83041f18be69b342c8779 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Volume Manager Extension Driver Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40380', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.113Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40380', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40380.json', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Calif.io in collaboration with Claude and Anthropic Research']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40380', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'To successfully exploit this vulnerability, an attacker or the targeted user would need to achieve a high level of control over a machine, as the attack requires access to processes typically restricted from average users.\nEssentially, the exploitation necessitates elevated privileges on the compromised machine due to the requirement of manipulating processes beyond the reach of standard user permissions.', 'title': 'According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows Volume Manager Extension Driver Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.2, 'attackVector': 'PHYSICAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 5.4, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40380', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40380.json', 'summary': 'CVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-40399 | msrc_CVE-2026-40399 | Windows TCP/IP Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40399.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 131e7a461ca913e3e821d498bc73576d99450ba3b2a084d8ce4d31e49f33a0b6 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40399', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.122Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40399', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40399.json', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['WARP & MORSE teams at Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40399', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40399', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40399.json', 'summary': 'CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}], 'product_status': {'fixed': ['10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27']}}]} |
CVE-2026-40405 | msrc_CVE-2026-40405 | Windows TCP/IP Denial of Service Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40405.json | ['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 9984ee055722073f79c42460d61c124dbb03401fa3fdcdcd749818ba90d1ee15 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40405', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.126Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40405', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40405.json', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40405', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40405', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40405.json', 'summary': 'CVE-2026-40405 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]} |
CVE-2026-40406 | msrc_CVE-2026-40406 | Windows TCP/IP Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40406.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 62a1cdfcd22fcd0fb811beaa06c6e89bea3bef9d5f8d5628be2d2fdbe5050b06 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40406', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.127Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40406', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40406.json', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40406', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploiting this vulnerability could allow the disclosure of certain kernel memory content.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40406', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40406.json', 'summary': 'CVE-2026-40406 Windows TCP/IP Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-40407 | msrc_CVE-2026-40407 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40407.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 99ae208d05404fe24cbb006b3538cf43050201bf8484a741ae0df0ba54766ce1 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Common Log File System Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40407', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.128Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40407.json', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40407', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Common Log File System Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40407', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40407.json', 'summary': 'CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['18', '19']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['18', '19']}, {'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['21', '23', '22', '20']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['15', '17', '16']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '12', '13']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['3', '4']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['3', '4']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['10', '11']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['30', '31']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-40408 | msrc_CVE-2026-40408 | Windows WAN ARP Driver Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40408.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 1f2d3cc267d1cd7fcb84a19017bbdbd7d53e2233b800316c188e9dd1d6df7358 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows WAN ARP Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40408', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.129Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40408', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40408.json', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['hazard']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40408', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows WAN ARP Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40408', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40408.json', 'summary': 'CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-40410 | msrc_CVE-2026-40410 | Windows SMB Client Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40410.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | dbd51f96546a512e2cf24c01368a593da2223978d2903efb26ef79411e2775ea | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows SMB Client Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40410', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.144Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40410', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40410.json', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40410', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation of this vulnerability requires an attacker to win a race condition.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows SMB Client Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.0, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40410', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40410.json', 'summary': 'CVE-2026-40410 Windows SMB Client Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29']}}]} |
CVE-2026-40414 | msrc_CVE-2026-40414 | Windows TCP/IP Denial of Service Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40414.json | ['Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | a9163663133ae7c45cb620cb7f2e0d9ebffd057df7e5a823e792e8105d095153 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40414', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.152Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40414', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40414.json', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Windows Attack Research & Protection (WARP) with <a href="https://microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40414', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the same network switch or virtual network.', 'title': 'According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': "In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to cause denial of service on the Hyper-V host environment.", 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.4, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40414', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40414.json', 'summary': 'CVE-2026-40414 Windows TCP/IP Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['18', '17', '16']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['15', '14']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['15', '14']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['13']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['20', '21', '19']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['25', '24']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['23', '22']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10853', '10855', '11569', '11571', '11572', '11923', '11924', '11931', '12097', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25']}}]} |
CVE-2026-40415 | msrc_CVE-2026-40415 | Windows TCP/IP Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40415.json | ['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 6277ab8f5e44f43753d24146ab730f1301f953650804c407e3fa085b25bc7929 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40415', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.154Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40415.json', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Windows Attack Research & Protection (WARP) with <a href="https://microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40415', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Successful exploitation requires the target system to be under sustained low-memory (memory pressure) conditions, which are not commonly present in normal operation. This makes the vulnerability difficult to reliably trigger, as the attacker must first induce or wait for a constrained memory state before exploitation becomes possible.', 'title': 'According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by sending specially crafted malicious traffic to a vulnerable server.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40415', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40415.json', 'summary': 'CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]} |
CVE-2026-40417 | msrc_CVE-2026-40417 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40417.json | ['Microsoft Dynamics 365 Business Central 2024 Release Wave 2 25.18', 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2 <25.18', 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 28.1', 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 <28.1', 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 26.12', 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 <26.12', 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 27.6', 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 <27.6'] | d4010ad87f67ce95329b861efee99f56c5c09ee96cf7c28283a5cfbd3486dd93 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40417', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.156Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40417.json', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/__nhienit__">Nhien Pham (@nhienit)</a> with Galaxy One']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1', 'branches': [{'name': '<28.1', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 <28.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '28.1', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2026 Release Wave 1 28.1', 'product_id': '21327'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Dynamics 365 Business Central Release Wave 1 2025', 'branches': [{'name': '<26.12', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 <26.12', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '26.12', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 1 2025 26.12', 'product_id': '21325'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Dynamics 365 Business Central Release Wave 2 2025', 'branches': [{'name': '<27.6', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 <27.6', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '27.6', 'product': {'name': 'Microsoft Dynamics 365 Business Central Release Wave 2 2025 27.6', 'product_id': '21326'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2', 'branches': [{'name': '<25.18', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2 <25.18', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '25.18', 'product': {'name': 'Microsoft Dynamics 365 Business Central 2024 Release Wave 2 25.18', 'product_id': '21324'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40417', 'cwe': {'id': 'CWE-1390', 'name': 'Weak Authentication'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40417', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40417.json', 'summary': 'CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'http://support.microsoft.com/kb/5093780', 'date': '2026-05-12T07:00:00.000Z', 'details': '28.1:Security Update:http://support.microsoft.com/kb/5093780', 'category': 'vendor_fix', 'product_ids': ['1']}, {'url': 'http://support.microsoft.com/kb/5086069', 'date': '2026-05-12T07:00:00.000Z', 'details': '26.12:Security Update:http://support.microsoft.com/kb/5086069', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'http://support.microsoft.com/kb/5086070', 'date': '2026-05-12T07:00:00.000Z', 'details': '27.6:Security Update:http://support.microsoft.com/kb/5086070', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'http://support.microsoft.com/kb/5086068', 'date': '2026-05-12T07:00:00.000Z', 'details': '25.18:Security Update:http://support.microsoft.com/kb/5086068', 'category': 'vendor_fix', 'product_ids': ['4']}], 'product_status': {'fixed': ['21324', '21325', '21326', '21327'], 'known_affected': ['1', '2', '3', '4']}}]} |
CVE-2026-40419 | msrc_CVE-2026-40419 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40419.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases'] | 8865638019cae82c66723ab7dd0e522346d33c2f0b96d006bd1fd2608eebb7ea | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Office Click-To-Run Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40419', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.157Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40419', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40419.json', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['0ccbbf129444eb66344ccafb92b00df4']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40419', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Office Click-To-Run Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40419', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40419.json', 'summary': 'CVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['8', '7', '6', '5', '4', '3', '2', '1']}], 'product_status': {'fixed': ['11573', '11574', '11762', '11763', '11952', '11953', '12420', '12421'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]} |
CVE-2026-40421 | msrc_CVE-2026-40421 | Microsoft Word Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40421.json | ['Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000'] | 9894f5512617eebb669e2883f886b2109a43f44bcdc5e24ee162eac8e8d5d1f2 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-40421', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.162Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40421', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40421.json', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['tiebuchen']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office 2019 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11573'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office 2019 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office 2019 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11574'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 32-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11762'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems <https://aka.ms/OfficeSecurityReleases', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft 365 Apps for Enterprise for 64-bit Systems https://aka.ms/OfficeSecurityReleases', 'product_id': '11763'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11952'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2021 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2021 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '11953'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 32-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 32-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12420'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC 2024 for 64-bit editions', 'branches': [{'name': '<https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions <https://aka.ms/OfficeSecurityReleases', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': 'https://aka.ms/OfficeSecurityReleases', 'product': {'name': 'Microsoft Office LTSC 2024 for 64-bit editions https://aka.ms/OfficeSecurityReleases', 'product_id': '12421'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (32-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) <16.0.5552.1000', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (32-bit edition) 16.0.5552.1000', 'product_id': '10746'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Word 2016 (64-bit edition)', 'branches': [{'name': '<16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) <16.0.5552.1000', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1000', 'product': {'name': 'Microsoft Word 2016 (64-bit edition) 16.0.5552.1000', 'product_id': '10747'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40421', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker must send a user a malicious Office file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'Exploiting this vulnerability could allow the disclosure of NTLM hashes.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality) but not all resources within the impacted component may be divulged to the attacker. The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability).', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L),but lead to no loss of availability (A:N) and integrity (I:N)? What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Word Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 3.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'LOW'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40421', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-40421.json', 'summary': 'CVE-2026-40421 Microsoft Word Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'date': '2026-05-12T07:00:00.000Z', 'details': 'https://aka.ms/OfficeSecurityReleases:Security Update:https://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates', 'category': 'vendor_fix', 'product_ids': ['8', '7', '6', '5', '4', '3', '2', '1']}, {'url': 'https://support.microsoft.com/help/5002858', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1000:Security Update:https://support.microsoft.com/help/5002858', 'category': 'vendor_fix', 'product_ids': ['10', '9']}], 'product_status': {'fixed': ['10746', '10747', '11573', '11574', '11762', '11763', '11952', '11953', '12420', '12421'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10']}}]} |
CVE-2026-41612 | msrc_CVE-2026-41612 | Visual Studio Code Information Disclosure Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41612.json | ['Visual Studio Code - Live Preview extension 0.4.19', 'Visual Studio Code - Live Preview extension <0.4.19'] | 7fa75596e06816f961cea73b7f1227d4d0bca2b3374571cc4c9e384662ce4f46 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Visual Studio Code Information Disclosure Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41612', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.191Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41612.json', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/aastikgakhar/">Aastik Gakhar</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code - Live Preview extension', 'branches': [{'name': '<0.4.19', 'product': {'name': 'Visual Studio Code - Live Preview extension <0.4.19', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '0.4.19', 'product': {'name': 'Visual Studio Code - Live Preview extension 0.4.19', 'product_id': '21333'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41612', 'cwe': {'id': 'CWE-23', 'name': 'Relative Path Traversal'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The type of information that could be disclosed if an attacker successfully exploited this vulnerability includes unauthorized access to the file system, specifically file path information.', 'title': 'What type of information could be disclosed by this vulnerability?', 'category': 'faq'}, {'text': 'Exploitation of this vulnerability requires that a user trigger the payload in the application.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Visual Studio Code Information Disclosure Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 4.8, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Information Disclosure', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41612', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41612.json', 'summary': 'CVE-2026-41612 Visual Studio Code Information Disclosure Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://marketplace.visualstudio.com/items?itemName=ms-vscode.live-server', 'date': '2026-05-12T07:00:00.000Z', 'details': '0.4.19:Security Update:https://marketplace.visualstudio.com/items?itemName=ms-vscode.live-server', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['21333'], 'known_affected': ['1']}}]} |
CVE-2026-41089 | msrc_CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41089.json | ['Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | c56767c7b9b24a4d525ca2beaad214b6586c2590a6ac44f2b79de927d56d98a5 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Netlogon Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41089', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.164Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41089.json', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Windows Attack Research & Protection (WARP) with <a href="https://microsoft.com/">Microsoft</a>']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41089', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could send a specially crafted network request to a Windows server that is acting as a domain controller. If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows Netlogon Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41089.json', 'summary': 'CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['7', '6']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['5', '4']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['9', '8']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['13', '12']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['11', '10']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10855', '11571', '11572', '11923', '11924', '12244', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13']}}]} |
CVE-2026-41094 | msrc_CVE-2026-41094 | Microsoft Data Formulator Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41094.json | ['Microsoft Data Formulator 0.7', 'Microsoft Data Formulator <0.7'] | 408e99e32b50ce278976e817ee5aa51940c42a054e00fe45cedd51581cbfef98 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Data Formulator Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41094', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.164Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41094', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41094.json', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/security_index">Yoshizawa</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Data Formulator', 'branches': [{'name': '<0.7', 'product': {'name': 'Microsoft Data Formulator <0.7', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '0.7', 'product': {'name': 'Microsoft Data Formulator 0.7', 'product_id': '21298'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41094', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The vulnerability can be exploited remotely over the network without administrative privileges, but exploitation requires user interaction to trigger processing of user‑supplied input by the affected service.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?', 'category': 'faq'}], 'title': 'Microsoft Data Formulator Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41094', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41094.json', 'summary': 'CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://pypi.org/project/data-formulator/', 'date': '2026-05-12T07:00:00.000Z', 'details': '0.7:Security Update:https://pypi.org/project/data-formulator/', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['21298'], 'known_affected': ['1']}}]} |
CVE-2026-41095 | msrc_CVE-2026-41095 | Data Deduplication Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41095.json | ['Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | d8d2f71da1c3568f7b5b32883b49a2becce85f06c83e338d9ba563b0cde38b5c | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Data Deduplication Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41095', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.165Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41095', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41095.json', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['ChenJian with Sea Security Orca Team']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41095', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Data Deduplication Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41095', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41095.json', 'summary': 'CVE-2026-41095 Data Deduplication Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['6', '7']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['9', '8']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['4', '5']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['4', '5']}], 'product_status': {'fixed': ['10483', '10543', '10816', '10855', '11571', '11572', '11923', '11924', '12244', '12436', '12437'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}}]} |
CVE-2026-41096 | msrc_CVE-2026-41096 | Windows DNS Client Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41096.json | ['Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 0ff0c825e44be9a5e94fe97d9f4c77dd6fff23167dca998ff3920118fa99c0cd | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DNS Client Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41096', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.177Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41096.json', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['WARP team at Microsoft']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41096', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could exploit this vulnerability by sending a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory. In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}], 'title': 'Windows DNS Client Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 8.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41096.json', 'summary': 'CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11']}}]} |
CVE-2026-41101 | msrc_CVE-2026-41101 | Microsoft Word for Android Spoofing Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41101.json | ['Microsoft Word for Android 16.0.19822.20190', 'Microsoft Word for Android <16.0.19822.20190'] | 3b7a1687ba7c96fa031dae0fbc4c978a99e048ab4eb4ae9c64f91ed5f9f4785e | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Word for Android Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41101', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.180Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41101', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41101.json', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/yanir_">Yanir Tsarimi</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Word for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft Word for Android <16.0.19822.20190', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft Word for Android 16.0.19822.20190', 'product_id': '11772'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41101', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Word for Android Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41101', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41101.json', 'summary': 'CVE-2026-41101 Microsoft Word for Android Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://play.google.com/store/apps/details?id=com.microsoft.office.word&hl=en_US', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11772'], 'known_affected': ['1']}}]} |
CVE-2026-41102 | msrc_CVE-2026-41102 | Microsoft PowerPoint for Android Spoofing Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41102.json | ['Microsoft PowerPoint for Android 16.0.19822.20190', 'Microsoft PowerPoint for Android <16.0.19822.20190'] | b0a3ef74550a2a042344fa6b92a93ab3ae5c8781c97bf7187cea14c4d7a7fa44 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft PowerPoint for Android Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41102', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.182Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41102', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41102.json', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://twitter.com/yanir_">Yanir Tsarimi</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft PowerPoint for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft PowerPoint for Android <16.0.19822.20190', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft PowerPoint for Android 16.0.19822.20190', 'product_id': '12032'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41102', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft PowerPoint for Android Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C', 'temporalScore': 6.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41102', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41102.json', 'summary': 'CVE-2026-41102 Microsoft PowerPoint for Android Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://play.google.com/store/apps/details?id=com.microsoft.office.powerpoint&hl=en_US', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://play.google.com/store/apps/details?id=com.microsoft.office.powerpoint&hl=en_US', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12032'], 'known_affected': ['1']}}]} |
CVE-2026-41109 | msrc_CVE-2026-41109 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41109.json | ['Visual Studio Code 1.119.1', 'Visual Studio Code <1.119.1'] | c7ef904a4643e52d1d7dd3fb27081a31a9aad033316329ae1fd26c0c9d30aeff | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41109', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.184Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41109.json', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Alexander Tan']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code', 'branches': [{'name': '<1.119.1', 'product': {'name': 'Visual Studio Code <1.119.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.119.1', 'product': {'name': 'Visual Studio Code 1.119.1', 'product_id': '11622'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41109', 'cwe': {'id': 'CWE-74', 'name': "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploitation of this vulnerability requires that an attacker convinces a user to open a maliciously crafted package file in Visual Studio.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by embedding malicious instructions in user input or external content that is processed, causing it to bypass guardrails, treat those instructions as trusted, and execute unintended actions such as retrieving sensitive data..', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}, {'text': 'Successful exploitation could bypass the path validation safeguards that check which files may be changed and require user approval for sensitive locations, allowing changes to protected files without the user’s knowledge or consent.', 'title': 'What kind of security feature could be bypassed by successfully exploiting this vulnerability?', 'category': 'faq'}], 'title': 'GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41109.json', 'summary': 'CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://code.visualstudio.com/updates/v1_119', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.119.1:Security Update:https://code.visualstudio.com/updates/v1_119', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11622'], 'known_affected': ['1']}}]} |
CVE-2026-41610 | msrc_CVE-2026-41610 | Visual Studio Code Security Feature Bypass Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41610.json | ['Visual Studio Code 1.119.1', 'Visual Studio Code <1.119.1'] | ebfa5856cfe12a97b098f75a62b334fabb8daea816ca32c0d540a91f4af6fdd2 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Visual Studio Code Security Feature Bypass Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41610', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.186Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41610.json', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://www.linkedin.com/in/tarek-nakkouch/">Tarek Nakkouch</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code', 'branches': [{'name': '<1.119.1', 'product': {'name': 'Visual Studio Code <1.119.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.119.1', 'product': {'name': 'Visual Studio Code 1.119.1', 'product_id': '11622'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41610', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'Exploitation would require a user to open or view a maliciously crafted notebook so that the affected content is rendered.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Visual Studio Code Security Feature Bypass Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C', 'temporalScore': 5.5, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Security Feature Bypass', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41610', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41610.json', 'summary': 'CVE-2026-41610 Visual Studio Code Security Feature Bypass Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://code.visualstudio.com/updates/v1_119', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.119.1:Security Update:https://code.visualstudio.com/updates/v1_119', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11622'], 'known_affected': ['1']}}]} |
CVE-2026-41611 | msrc_CVE-2026-41611 | Visual Studio Code Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41611.json | ['Visual Studio Code 1.119.1', 'Visual Studio Code <1.119.1'] | 52d85fe10a788551ee11125c3cedf069b00cfee915ec0a4e16f731300136cdb6 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Visual Studio Code Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-41611', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.187Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41611.json', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft']}, {'names': ['Microsoft']}, {'names': ['<a href="https://www.linkedin.com/in/balgan/">Tiago Henriques</a> with <a href="https://coalitioninc.com/">Coalition inc</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Visual Studio Code', 'branches': [{'name': '<1.119.1', 'product': {'name': 'Visual Studio Code <1.119.1', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.119.1', 'product': {'name': 'Visual Studio Code 1.119.1', 'product_id': '11622'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-41611', 'cwe': {'id': 'CWE-80', 'name': 'Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}, {'text': 'Exploitation of this vulnerability requires that a user trigger the payload in the application.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}], 'title': 'Visual Studio Code Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41611', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-41611.json', 'summary': 'CVE-2026-41611 Visual Studio Code Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://code.visualstudio.com/updates/v1_119', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.119.1:Security Update:https://code.visualstudio.com/updates/v1_119', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['11622'], 'known_affected': ['1']}}]} |
CVE-2026-42831 | msrc_CVE-2026-42831 | Microsoft Office Remote Code Execution Vulnerability | Critical | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42831.json | ['Microsoft Office LTSC for Mac 2021 16.109.26051019', 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'Microsoft Office for Android 16.0.19822.20190', 'Microsoft Office for Android <16.0.19822.20190'] | 06d21ef4938d95d3fc040171360db886562ef41e1ac5504cd5f2aa0338d5057a | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42831', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.208Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42831.json', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['pwn2addr']}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft Office LTSC for Mac 2021', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 <16.109.26051019', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2021 16.109.26051019', 'product_id': '11951'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office for Android', 'branches': [{'name': '<16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android <16.0.19822.20190', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.19822.20190', 'product': {'name': 'Microsoft Office for Android 16.0.19822.20190', 'product_id': '12155'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft Office LTSC for Mac 2024', 'branches': [{'name': '<16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 <16.109.26051019', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.109.26051019', 'product': {'name': 'Microsoft Office LTSC for Mac 2024 16.109.26051019', 'product_id': '12440'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42831', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.', 'title': 'According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?', 'category': 'faq'}, {'text': 'An attacker must send a user a malicious Office file and convince them to open it.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'No, the Preview Pane is not an attack vector.', 'title': 'Is the Preview Pane an attack vector for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft Office Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42831', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42831.json', 'summary': 'CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://go.microsoft.com/fwlink/p/?linkid=831049', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.109.26051019:Security Update:https://go.microsoft.com/fwlink/p/?linkid=831049', 'category': 'vendor_fix', 'product_ids': ['3', '1']}, {'url': 'https://support.google.com/googleplay/answer/113412?hl=en', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19822.20190:Security Update:https://support.google.com/googleplay/answer/113412?hl=en', 'category': 'vendor_fix', 'product_ids': ['2']}], 'product_status': {'fixed': ['11951', '12155', '12440'], 'known_affected': ['1', '2', '3']}}]} |
CVE-2026-42896 | msrc_CVE-2026-42896 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42896.json | ['Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | a994ba028d49d1fdd5e99e29d4288565136af6fdc4730677d5d8a9456dd624d3 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42896', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.220Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42896', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42896.json', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['namnp with <a href="https://x.com/vcslab">Viettel Cyber Security</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42896', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows DWM Core Library Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42896', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42896.json', 'summary': 'CVE-2026-42896 Windows DWM Core Library Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8']}}]} |
CVE-2026-42899 | msrc_CVE-2026-42899 | ASP.NET Core Denial of Service Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42899.json | ['.NET 10.0 installed on Linux 10.0.8', '.NET 10.0 installed on Linux <10.0.8', '.NET 10.0 installed on Mac OS 10.0.8', '.NET 10.0 installed on Mac OS <10.0.8', '.NET 10.0 installed on Windows 10.0.8', '.NET 10.0 installed on Windows <10.0.8', '.NET 8.0 installed on Linux 8.0.27', '.NET 8.0 installed on Linux <8.0.27', '.NET 8.0 installed on Mac OS 8.0.27', '.NET 8.0 installed on Mac OS <8.0.27', '.NET 8.0 installed on Windows 8.0.27', '.NET 8.0 installed on Windows <8.0.27', '.NET 9.0 installed on Linux 9.0.16', '.NET 9.0 installed on Linux <9.0.16', '.NET 9.0 installed on Mac OS 9.0.16', '.NET 9.0 installed on Mac OS <9.0.16', '.NET 9.0 installed on Windows 9.0.16', '.NET 9.0 installed on Windows <9.0.16'] | eb084aa49425b1d35c5307655f5891f698c725d0f7f43b38d9712c1b4daea717 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'ASP.NET Core Denial of Service Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-42899', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.223Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42899.json', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['hamayanhamayan']}, {'names': ['<a href="https://www.linkedin.com/in/abdul-rehman---/">Muhammad Abdul Rehman</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': '.NET 8.0 installed on Windows', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Windows <8.0.27', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Windows 8.0.27', 'product_id': '12414'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Linux', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Linux <9.0.16', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Linux 9.0.16', 'product_id': '12432'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 8.0 installed on Mac OS', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Mac OS <8.0.27', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Mac OS 8.0.27', 'product_id': '12416'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 8.0 installed on Linux', 'branches': [{'name': '<8.0.27', 'product': {'name': '.NET 8.0 installed on Linux <8.0.27', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '8.0.27', 'product': {'name': '.NET 8.0 installed on Linux 8.0.27', 'product_id': '12415'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Windows', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Windows <9.0.16', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Windows 9.0.16', 'product_id': '12434'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 9.0 installed on Mac OS', 'branches': [{'name': '<9.0.16', 'product': {'name': '.NET 9.0 installed on Mac OS <9.0.16', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '9.0.16', 'product': {'name': '.NET 9.0 installed on Mac OS 9.0.16', 'product_id': '12433'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 10.0 installed on Mac OS', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Mac OS <10.0.8', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Mac OS 10.0.8', 'product_id': '20838'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 10.0 installed on Linux', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Linux <10.0.8', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Linux 10.0.8', 'product_id': '20839'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': '.NET 10.0 installed on Windows', 'branches': [{'name': '<10.0.8', 'product': {'name': '.NET 10.0 installed on Windows <10.0.8', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.8', 'product': {'name': '.NET 10.0 installed on Windows 10.0.8', 'product_id': '20837'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-42899', 'cwe': {'id': 'CWE-835', 'name': "Loop with Unreachable Exit Condition ('Infinite Loop')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}], 'title': 'ASP.NET Core Denial of Service Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'NONE'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9']}], 'threats': [{'details': 'Denial of Service', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-42899.json', 'summary': 'CVE-2026-42899 ASP.NET Core Denial of Service Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5093447', 'date': '2026-05-12T07:00:00.000Z', 'details': '8.0.27:Security Update:https://support.microsoft.com/help/5093447', 'category': 'vendor_fix', 'product_ids': ['9', '7', '8']}, {'url': 'https://support.microsoft.com/help/5093448', 'date': '2026-05-12T07:00:00.000Z', 'details': '9.0.16:Security Update:https://support.microsoft.com/help/5093448', 'category': 'vendor_fix', 'product_ids': ['6', '4', '5']}, {'url': 'https://support.microsoft.com/help/5093446', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.8:Security Update:https://support.microsoft.com/help/5093446', 'category': 'vendor_fix', 'product_ids': ['2', '1', '3']}], 'product_status': {'fixed': ['12414', '12415', '12416', '12432', '12433', '12434', '20837', '20838', '20839'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9']}}]} |
CVE-2026-33110 | msrc_CVE-2026-33110 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33110.json | ['Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280'] | 415612b0792f7c9b473df2a14952329db91439bbe26b4907c33bf8dd9daf7c90 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33110', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.238Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33110.json', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['f7d8c52bec79e42795cf15888b85cbad']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Microsoft SharePoint Enterprise Server 2016', 'branches': [{'name': '<16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 <16.0.5552.1002', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '16.0.5552.1002', 'product': {'name': 'Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002', 'product_id': '10950'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server 2019', 'branches': [{'name': '<16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 <16.0.10417.20128', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '16.0.10417.20128', 'product': {'name': 'Microsoft SharePoint Server 2019 16.0.10417.20128', 'product_id': '11585'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Microsoft SharePoint Server Subscription Edition', 'branches': [{'name': '<16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition <16.0.19725.20280', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '16.0.19725.20280', 'product': {'name': 'Microsoft SharePoint Server Subscription Edition 16.0.19725.20280', 'product_id': '11961'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33110', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.', 'title': 'I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?', 'category': 'faq'}, {'text': 'Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.', 'title': 'According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}, {'text': 'The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?', 'category': 'faq'}], 'title': 'Microsoft SharePoint Server Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33110', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33110.json', 'summary': 'CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5002868', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.5552.1002:Security Update:https://support.microsoft.com/help/5002868', 'category': 'vendor_fix', 'product_ids': ['3']}, {'url': 'https://support.microsoft.com/help/5002870', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.10417.20128:Security Update:https://support.microsoft.com/help/5002870', 'category': 'vendor_fix', 'product_ids': ['2']}, {'url': 'https://support.microsoft.com/help/5002863', 'date': '2026-05-12T07:00:00.000Z', 'details': '16.0.19725.20280:Security Update:https://support.microsoft.com/help/5002863', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['10950', '11585', '11961'], 'known_affected': ['1', '2', '3']}}]} |
CVE-2026-33833 | msrc_CVE-2026-33833 | Azure Machine Learning Notebook Spoofing Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33833.json | ['Azure Machine Learning 1.7.6', 'Azure Machine Learning <1.7.6'] | df188484e4192f1b33e79d2b9c9bd03247bf3c8711f8471e6ed54a5e75e7a0fb | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Azure Machine Learning Notebook Spoofing Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33833', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.247Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33833', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33833.json', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Jianyang Song']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Azure Machine Learning', 'branches': [{'name': '<1.7.6', 'product': {'name': 'Azure Machine Learning <1.7.6', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '1.7.6', 'product': {'name': 'Azure Machine Learning 1.7.6', 'product_id': '12152'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33833', 'cwe': {'id': 'CWE-74', 'name': "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could view sensitive information, (Confidentiality), and make some changes to disclosed information (Integrity), but they would not be able to affect Availability.', 'title': 'According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), and some loss of integrity (I:L), but no loss of availability (A:N). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'Exploitation would require a user to open or view a maliciously crafted notebook so that the affected content is rendered.', 'title': 'According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?', 'category': 'faq'}, {'text': 'An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.', 'title': 'According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could create or import a specially crafted Azure ML notebook containing malicious styling content in a Markdown cell, which may be rendered when the notebook is viewed and could expose sensitive information displayed within the Azure ML web interface.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Azure Machine Learning Notebook Spoofing Vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C', 'temporalScore': 7.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1']}], 'threats': [{'details': 'Spoofing', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33833', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33833.json', 'summary': 'CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://dev.azure.com/devdiv/OnlineServices/_artifacts/feed/AzureNotebooksEntry@Local/Npm/@azure-notebooks/versions/overview', 'date': '2026-05-12T07:00:00.000Z', 'details': '1.7.6:Security Update:https://dev.azure.com/devdiv/OnlineServices/_artifacts/feed/AzureNotebooksEntry@Local/Npm/@azure-notebooks/versions/overview', 'category': 'vendor_fix', 'product_ids': ['1']}], 'product_status': {'fixed': ['12152'], 'known_affected': ['1']}}]} |
CVE-2026-33835 | msrc_CVE-2026-33835 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33835.json | ['Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | f4ff64ce30e161fbee167dfc6e4dbdd97ed8545c5cfe454897ca181cfa765e20 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33835', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.248Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33835.json', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/_dez">Joe Desimone</a> with Elastic Security']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33835', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33835.json', 'summary': 'CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['21', '23', '22', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['16', '17', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}], 'product_status': {'fixed': ['11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23']}}]} |
CVE-2026-33837 | msrc_CVE-2026-33837 | Windows TCP/IP Local Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33837.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 1ecfec3a772050fea897b7db97160f41134c7875fbcaf5f5b96b8b3d6269ba0f | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows TCP/IP Local Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33837', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.260Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33837', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33837.json', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['<a href="https://x.com/h4urek">h4urek</a> with <a href="https://secsys.fudan.edu.cn/">secsys lab</a>']}, {'names': ['<a href="https://x.com/h4urek">h4urek</a> with <a href="https://secsys.fudan.edu.cn/">secsys lab</a>']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33837', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker could exploit this vulnerability locally by running code with limited privileges and then interacting with the tcpip.sys kernel driver to gain elevated (kernel-level) privileges on the system.', 'title': 'How could an attacker exploit this vulnerability?', 'category': 'faq'}], 'title': 'Windows TCP/IP Local Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33837', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33837.json', 'summary': 'CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-33838 | msrc_CVE-2026-33838 | Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33838.json | ['Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'Windows Server 2012 6.2.9200.26079', 'Windows Server 2012 <6.2.9200.26079', 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'Windows Server 2012 R2 6.3.9600.23181', 'Windows Server 2012 R2 <6.3.9600.23181', 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'Windows Server 2016 10.0.14393.9140', 'Windows Server 2016 <10.0.14393.9140', 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'Windows Server 2019 10.0.17763.8755', 'Windows Server 2019 <10.0.17763.8755', 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'Windows Server 2022 10.0.20348.5139', 'Windows Server 2022 <10.0.20348.5139', 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | c826c87ddf0dafb64d0cc03a508eacfec58c79599ed00fb8a6f5c1029fcf994e | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-33838', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.267Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33838', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33838.json', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Anonymous working with TrendAI Zero Day Initiative']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows 10 Version 1809 for 32-bit Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems <10.0.17763.8755', 'product_id': '23'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for 32-bit Systems 10.0.17763.8755', 'product_id': '11568'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1809 for x64-based Systems', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems <10.0.17763.8755', 'product_id': '22'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows 10 Version 1809 for x64-based Systems 10.0.17763.8755', 'product_id': '11569'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 <10.0.17763.8755', 'product_id': '21'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 10.0.17763.8755', 'product_id': '11571'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2019 (Server Core installation)', 'branches': [{'name': '<10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) <10.0.17763.8755', 'product_id': '20'}, 'category': 'product_version_range'}, {'name': '10.0.17763.8755', 'product': {'name': 'Windows Server 2019 (Server Core installation) 10.0.17763.8755', 'product_id': '11572'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 <10.0.20348.5139', 'product_id': '19'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 10.0.20348.5139', 'product_id': '11923'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022 (Server Core installation)', 'branches': [{'name': '<10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) <10.0.20348.5139', 'product_id': '18'}, 'category': 'product_version_range'}, {'name': '10.0.20348.5139', 'product': {'name': 'Windows Server 2022 (Server Core installation) 10.0.20348.5139', 'product_id': '11924'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems <10.0.19044.7291', 'product_id': '17'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for 32-bit Systems 10.0.19044.7291', 'product_id': '11929'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems <10.0.19044.7291', 'product_id': '16'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for ARM64-based Systems 10.0.19044.7291', 'product_id': '11930'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 21H2 for x64-based Systems', 'branches': [{'name': '<10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems <10.0.19044.7291', 'product_id': '15'}, 'category': 'product_version_range'}, {'name': '10.0.19044.7291', 'product': {'name': 'Windows 10 Version 21H2 for x64-based Systems 10.0.19044.7291', 'product_id': '11931'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for x64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems <10.0.19045.7291', 'product_id': '14'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for x64-based Systems 10.0.19045.7291', 'product_id': '12097'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems <10.0.19045.7291', 'product_id': '13'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for ARM64-based Systems 10.0.19045.7291', 'product_id': '12098'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 22H2 for 32-bit Systems', 'branches': [{'name': '<10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems <10.0.19045.7291', 'product_id': '12'}, 'category': 'product_version_range'}, {'name': '10.0.19045.7291', 'product': {'name': 'Windows 10 Version 22H2 for 32-bit Systems 10.0.19045.7291', 'product_id': '12099'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '5'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems <10.0.26200.8457', 'product_id': '4'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for ARM64-based Systems 10.0.26200.8457', 'product_id': '20437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 25H2 for x64-based Systems', 'branches': [{'name': '<10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems <10.0.26200.8457', 'product_id': '3'}, 'category': 'product_version_range'}, {'name': '10.0.26200.8457', 'product': {'name': 'Windows 11 Version 25H2 for x64-based Systems 10.0.26200.8457', 'product_id': '20438'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems <10.0.22631.7079', 'product_id': '11'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for ARM64-based Systems 10.0.22631.7079', 'product_id': '12242'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 23H2 for x64-based Systems', 'branches': [{'name': '<10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems <10.0.22631.7079', 'product_id': '10'}, 'category': 'product_version_range'}, {'name': '10.0.22631.7079', 'product': {'name': 'Windows 11 Version 23H2 for x64-based Systems 10.0.22631.7079', 'product_id': '12243'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'branches': [{'name': '<10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) <10.0.25398.2330', 'product_id': '9'}, 'category': 'product_version_range'}, {'name': '10.0.25398.2330', 'product': {'name': 'Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.2330', 'product_id': '12244'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for ARM64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems <10.0.26100.8457', 'product_id': '8'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for ARM64-based Systems 10.0.26100.8457', 'product_id': '12389'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 24H2 for x64-based Systems', 'branches': [{'name': '<10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems <10.0.26100.8457', 'product_id': '7'}, 'category': 'product_version_range'}, {'name': '10.0.26100.8457', 'product': {'name': 'Windows 11 Version 24H2 for x64-based Systems 10.0.26100.8457', 'product_id': '12390'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '6'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 version 26H1 for x64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems <10.0.28000.2113', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 version 26H1 for x64-based Systems 10.0.28000.2113', 'product_id': '20853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 11 Version 26H1 for ARM64-based Systems', 'branches': [{'name': '<10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems <10.0.28000.2113', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.28000.2113', 'product': {'name': 'Windows 11 Version 26H1 for ARM64-based Systems 10.0.28000.2113', 'product_id': '20854'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for 32-bit Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems <10.0.14393.9140', 'product_id': '26'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for 32-bit Systems 10.0.14393.9140', 'product_id': '10852'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows 10 Version 1607 for x64-based Systems', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems <10.0.14393.9140', 'product_id': '25'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows 10 Version 1607 for x64-based Systems 10.0.14393.9140', 'product_id': '10853'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 <10.0.14393.9140', 'product_id': '27'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 10.0.14393.9140', 'product_id': '10816'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2016 (Server Core installation)', 'branches': [{'name': '<10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) <10.0.14393.9140', 'product_id': '24'}, 'category': 'product_version_range'}, {'name': '10.0.14393.9140', 'product': {'name': 'Windows Server 2016 (Server Core installation) 10.0.14393.9140', 'product_id': '10855'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 <6.2.9200.26079', 'product_id': '31'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 6.2.9200.26079', 'product_id': '10378'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 (Server Core installation)', 'branches': [{'name': '<6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) <6.2.9200.26079', 'product_id': '30'}, 'category': 'product_version_range'}, {'name': '6.2.9200.26079', 'product': {'name': 'Windows Server 2012 (Server Core installation) 6.2.9200.26079', 'product_id': '10379'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 <6.3.9600.23181', 'product_id': '29'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 6.3.9600.23181', 'product_id': '10483'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2012 R2 (Server Core installation)', 'branches': [{'name': '<6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) <6.3.9600.23181', 'product_id': '28'}, 'category': 'product_version_range'}, {'name': '6.3.9600.23181', 'product': {'name': 'Windows Server 2012 R2 (Server Core installation) 6.3.9600.23181', 'product_id': '10543'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33838', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.', 'title': 'What privileges could be gained by an attacker who successfully exploited this vulnerability?', 'category': 'faq'}], 'title': 'Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}], 'threats': [{'details': 'Elevation of Privilege', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33838', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-33838.json', 'summary': 'CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087538', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.17763.8755:Security Update:https://support.microsoft.com/help/5087538', 'category': 'vendor_fix', 'product_ids': ['23', '22', '21', '20']}, {'url': 'https://support.microsoft.com/help/5087545', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5139:Security Update:https://support.microsoft.com/help/5087545', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087424', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.20348.5074:Security Hotpatch Update:https://support.microsoft.com/help/5087424', 'category': 'vendor_fix', 'product_ids': ['19', '18']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19044.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['17', '16', '15']}, {'url': 'https://support.microsoft.com/help/5087544', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.19045.7291:Security Update:https://support.microsoft.com/help/5087544', 'category': 'vendor_fix', 'product_ids': ['14', '13', '12']}, {'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['5', '6']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26200.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['4', '3']}, {'url': 'https://support.microsoft.com/help/5087420', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.22631.7079:Security Update:https://support.microsoft.com/help/5087420', 'category': 'vendor_fix', 'product_ids': ['11', '10']}, {'url': 'https://support.microsoft.com/help/5087541', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.25398.2330:Security Update:https://support.microsoft.com/help/5087541', 'category': 'vendor_fix', 'product_ids': ['9']}, {'url': 'https://support.microsoft.com/help/5089549', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8457:Security Update:https://support.microsoft.com/help/5089549', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089466', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.8390:Security Hotpatch Update:https://support.microsoft.com/help/5089466', 'category': 'vendor_fix', 'product_ids': ['8', '7']}, {'url': 'https://support.microsoft.com/help/5089548', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.28000.2113:Security Update:https://support.microsoft.com/help/5089548', 'category': 'vendor_fix', 'product_ids': ['2', '1']}, {'url': 'https://support.microsoft.com/help/5087537', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.14393.9140:Security Update:https://support.microsoft.com/help/5087537', 'category': 'vendor_fix', 'product_ids': ['26', '25', '27', '24']}, {'url': 'https://support.microsoft.com/help/5087470', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.2.9200.26079:Monthly Rollup:https://support.microsoft.com/help/5087470', 'category': 'vendor_fix', 'product_ids': ['31', '30']}, {'url': 'https://support.microsoft.com/help/5087471', 'date': '2026-05-12T07:00:00.000Z', 'details': '6.3.9600.23181:Monthly Rollup:https://support.microsoft.com/help/5087471', 'category': 'vendor_fix', 'product_ids': ['29', '28']}], 'product_status': {'fixed': ['10378', '10379', '10483', '10543', '10816', '10852', '10853', '10855', '11568', '11569', '11571', '11572', '11923', '11924', '11929', '11930', '11931', '12097', '12098', '12099', '12242', '12243', '12244', '12389', '12390', '12436', '12437', '20437', '20438', '20853', '20854'], 'known_affected': ['1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '11', '12', '13', '14', '15', '16', '17', '18', '19', '20', '21', '22', '23', '24', '25', '26', '27', '28', '29', '30', '31']}}]} |
CVE-2026-34332 | msrc_CVE-2026-34332 | Windows Kernel-Mode Driver Remote Code Execution Vulnerability | Important | 2026-05-12 10:00:00+03:00 | 2026-05-12 10:00:00+03:00 | https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34332.json | ['Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'Windows Server 2025 10.0.26100.32860', 'Windows Server 2025 <10.0.26100.32860'] | 5fda69f48814d24c9c6196b43da1ca10feb9182e8e11c0df819da38cbe1173c6 | 2026-05-29 20:36:27.484886+03:00 | 2026-05-29 20:36:27.484886+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The information provided in the Microsoft Knowledge Base is provided \\"as is\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Required. The vulnerability documented by this CVE requires customer action to resolve.', 'title': 'Customer Action', 'category': 'general'}], 'title': 'Windows Kernel-Mode Driver Remote Code Execution Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'msrc_CVE-2026-34332', 'status': 'final', 'version': '1', 'generator': {'date': '2026-05-28T01:40:57.267Z', 'engine': {'name': 'MSRC Generator', 'version': '1.0'}}, 'revision_history': [{'date': '2026-05-12T07:00:00.000Z', 'number': '1', 'summary': 'Information published.', 'legacy_version': '1'}], 'current_release_date': '2026-05-12T07:00:00.000Z', 'initial_release_date': '2026-05-12T07:00:00.000Z'}, 'publisher': {'name': 'Microsoft Security Response Center', 'category': 'vendor', 'namespace': 'https://msrc.microsoft.com', 'contact_details': 'secure@microsoft.com'}, 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34332', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34332.json', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1', 'summary': 'Microsoft Exploitability Index', 'category': 'external'}, {'url': 'https://support.microsoft.com/lifecycle', 'summary': 'Microsoft Support Lifecycle', 'category': 'external'}, {'url': 'https://www.first.org/cvss', 'summary': 'Common Vulnerability Scoring System', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}, 'text': 'Public'}, 'acknowledgments': [{'names': ['Microsoft Offensive Research & Security Engineering']}], 'aggregate_severity': {'text': 'Important', 'namespace': 'https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system'}}, 'product_tree': {'branches': [{'name': 'Windows Server 2025 (Server Core installation)', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) <10.0.26100.32860', 'product_id': '1'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 (Server Core installation) 10.0.26100.32860', 'product_id': '12437'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Windows Server 2025', 'branches': [{'name': '<10.0.26100.32860', 'product': {'name': 'Windows Server 2025 <10.0.26100.32860', 'product_id': '2'}, 'category': 'product_version_range'}, {'name': '10.0.26100.32860', 'product': {'name': 'Windows Server 2025 10.0.26100.32860', 'product_id': '12436'}, 'category': 'product_version'}], 'category': 'product_name'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-34332', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Microsoft', 'title': 'Assigning CNA', 'category': 'general'}, {'text': 'Exploitation of this vulnerability requires an authorized attacker on the domain to wait for a user to initiate a connection to a malicious server that the attacker has set up prior to the user connecting.', 'title': 'According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are low (PR:L). What does that mean for this vulnerability?', 'category': 'faq'}, {'text': 'An attacker could exploit this vulnerability by sending a specially crafted NVMe over Fabrics (NVMe‑oF) response message during the connection handshake process that contains an invalid header length value.', 'title': 'How could an attacker exploit the vulnerability?', 'category': 'faq'}], 'title': 'Windows Kernel-Mode Driver Remote Code Execution Vulnerability', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.0, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C', 'temporalScore': 7.0, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'environmentalsScore': 0.0, 'exploitCodeMaturity': 'UNPROVEN', 'confidentialityImpact': 'HIGH'}, 'products': ['1', '2']}], 'threats': [{'details': 'Remote Code Execution', 'category': 'impact'}, {'details': 'Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely', 'category': 'exploit_status'}], 'references': [{'url': 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34332', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - HTML', 'category': 'self'}, {'url': 'https://msrc.microsoft.com/csaf/advisories/2026/msrc_cve-2026-34332.json', 'summary': 'CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability - CSAF', 'category': 'self'}], 'remediations': [{'url': 'https://support.microsoft.com/help/5087539', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32860:Security Update:https://support.microsoft.com/help/5087539', 'category': 'vendor_fix', 'product_ids': ['1', '2']}, {'url': 'https://support.microsoft.com/help/5087423', 'date': '2026-05-12T07:00:00.000Z', 'details': '10.0.26100.32772:Security Hotpatch Update:https://support.microsoft.com/help/5087423', 'category': 'vendor_fix', 'product_ids': ['1', '2']}], 'product_status': {'fixed': ['12436', '12437'], 'known_affected': ['1', '2']}}]} |